{"id":1934,"date":"2013-01-14T20:40:40","date_gmt":"2013-01-14T20:40:40","guid":{"rendered":"https:\/\/blogs.swarthmore.edu\/its\/?p=1934"},"modified":"2013-01-14T20:40:40","modified_gmt":"2013-01-14T20:40:40","slug":"java-the-hackers-best-friend","status":"publish","type":"post","link":"https:\/\/blogs.swarthmore.edu\/its\/2013\/01\/14\/java-the-hackers-best-friend\/","title":{"rendered":"Java &#8211; The Hacker&#8217;s Best Friend"},"content":{"rendered":"<p>Some of you may have heard that a significant security vulnerability was disclosed recently that affects pretty much all versions of Java. Oracle (who now owns Java) seemed to be dragging their feet on providing a fix until they felt some heat from the U.S. Government. A fix was made available today but only for users of Java version 7. Java runs on all operating systems so Mac users are impacted along with PC users. \u00a0<em>Note:<\/em> <em>there won&#8217;t be a fix available for Mac users with <span style=\"text-decoration: underline;\">Snow Leopard or earlier<\/span> so your best option is to totally disable Java.<\/em><\/p>\n<p style=\"padding-left: 30px;\"><strong>How do you know if you have Java installed?<\/strong><br \/>\nClick on this link to find out: <a title=\"Do you have Java installed?\" href=\"http:\/\/www.java.com\/en\/download\/installed.jsp\">http:\/\/www.java.com\/en\/download\/installed.jsp<\/a><\/p>\n<p>If you don\u2019t need Java (not to be confused with JavaScript), you should uninstall it or, for Windows, disable browser use in the Java Control Panel (see <a title=\"Disabling Java in your Browser\" href=\"http:\/\/www.java.com\/en\/download\/help\/disable_browser.xml\">http:\/\/www.java.com\/en\/download\/help\/disable_browser.xml<\/a>). In addition to the <a title=\"Homeland Security warns to disable Java\" href=\"http:\/\/www.zdnet.com\/homeland-security-warns-to-disable-java-amid-zero-day-flaw-7000009713\/\">Department of Homeland Security<\/a>, many security industry experts are recommending that <span style=\"text-decoration: underline;\">Java be disabled immediately<\/span> (fix or no fix).<\/p>\n<p>Unfortunately, a number of us require Java for applications that we use at work (including for web apps like GoToMeeting and WebEx).\u00a0 So, if you absolutely must keep Java installed, you should strongly consider disabling Java in <strong>all<\/strong> your browsers except the one that you access Java-based applications with.\u00a0 Use that one browser just for your Java-based applications.\u00a0 Use your other browsers, the ones with Java disabled, to access the Internet.<\/p>\n<p>Below are steps to disable Java in all browsers except Internet Explorer (so IE is a good choice for the browser where Java is left enabled).<\/p>\n<p><span style=\"text-decoration: underline;\">Firefox<\/span><br \/>\n1.\u00a0\u00a0 \u00a0Click on the <strong>Firefox<\/strong> tab (or Tools) then and then select <strong>Add-ons<\/strong><br \/>\n2.\u00a0\u00a0 \u00a0In the Add-ons Manager window, select <strong>Plugins<\/strong><br \/>\n3.\u00a0\u00a0 \u00a0Click <strong>Java (TM) Platform<\/strong> plugin to select it<br \/>\n4.\u00a0\u00a0 \u00a0Click <strong>Disable<\/strong> (if the button displays Enable then Java is already disabled)<\/p>\n<p><span style=\"text-decoration: underline;\">Safari<\/span><br \/>\n1.\u00a0\u00a0 \u00a0Choose Safari <strong>Preferences<\/strong><br \/>\n2.\u00a0\u00a0 \u00a0Choose the <strong>Security<\/strong> option<br \/>\n3.\u00a0\u00a0 \u00a0Deselect <strong>Enable Java<\/strong><br \/>\n4.\u00a0\u00a0 \u00a0Close Safari Preferences window<\/p>\n<p><span style=\"text-decoration: underline;\">Chrome<\/span><br \/>\n1.\u00a0\u00a0 \u00a0Type <strong>about:plugins<\/strong> in the browser address bar.<br \/>\n2.\u00a0\u00a0 \u00a0In the Plugins panel, scroll to the Java section. Click <strong>Disable<\/strong> to disable the Java Plug-in.<br \/>\n3.\u00a0\u00a0 \u00a0Close and restart the browser to enable the changes<\/p>\n<p>While you\u2019re diligently dealing with this Java mess, you should go ahead and update your installed Adobe products (Reader, Flash and AIR) and install the most recent Microsoft patches (for Windows machines).\u00a0 Significant security vulnerabilities in these software packages were also patched recently and should be installed as soon as possible.<\/p>\n<p>With all these patches needing installation for various applications, it\u2019s difficult to keep track.\u00a0 I still recommend using BrowserCheck from Qualys (<a title=\"Qualys BrowserCheck\" href=\"https:\/\/browsercheck.qualys.com\/\">browsercheck.qualys.com<\/a>) for what amounts to a quick, one-click assessment of missing security patches on your Mac or PC.\u00a0 It\u2019s free and there\u2019s no registration required.\u00a0 I\u2019ve written about BrowserCheck previously here:<\/p>\n<p><a href=\"https:\/\/blogs.swarthmore.edu\/its\/2010\/10\/18\/give-your-computer-a-fighting-chance\/\">https:\/\/blogs.swarthmore.edu\/its\/2010\/10\/18\/give-your-computer-a-fighting-chance\/<\/a><br \/>\n<a href=\"https:\/\/blogs.swarthmore.edu\/its\/2011\/06\/15\/update-your-browser-%E2%80%93-save-your-computer\/\">https:\/\/blogs.swarthmore.edu\/its\/2011\/06\/15\/update-your-browser-save-your-computer\/<\/a><br \/>\n<a href=\"https:\/\/blogs.swarthmore.edu\/its\/2012\/03\/12\/update-everything\/\">https:\/\/blogs.swarthmore.edu\/its\/2012\/03\/12\/update-everything\/<\/a><\/p>\n<p>In summary, if you don&#8217;t need Java, get rid of it.<br \/>\nNick<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some of you may have heard that a significant security vulnerability was disclosed recently that affects pretty much all versions of Java. Oracle (who now owns Java) seemed to be dragging their feet on providing a fix until they felt some heat from the U.S. Government. A fix was made available today but only for users of Java version 7. Java runs on all operating systems so Mac users are impacted along with PC users. \u00a0Note: there won&#8217;t be a fix available for Mac users with Snow Leopard or earlier so your best option is to totally disable Java. How &hellip; <a href=\"https:\/\/blogs.swarthmore.edu\/its\/2013\/01\/14\/java-the-hackers-best-friend\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Java &#8211; The Hacker&#8217;s Best Friend<\/span><\/a><\/p>\n","protected":false},"author":41,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[96,97],"tags":[],"class_list":["post-1934","post","type-post","status-publish","format-standard","hentry","category-security","category-software"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/ph2nPL-vc","_links":{"self":[{"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/posts\/1934","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/users\/41"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/comments?post=1934"}],"version-history":[{"count":17,"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/posts\/1934\/revisions"}],"predecessor-version":[{"id":1946,"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/posts\/1934\/revisions\/1946"}],"wp:attachment":[{"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/media?parent=1934"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/categories?post=1934"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.swarthmore.edu\/its\/wp-json\/wp\/v2\/tags?post=1934"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}