Homeland Security Warning: Disable Java in Browsers: New Zero Day Security Flaw Found

 

It’s a pretty rare event when DHS warns to disable the Java in your browser, but they have because of a Zero Day security flaw which allows infected applets to infect your computer via your browser and allow elevation of privileges to occur.

Once this occurs, your computer will no longer keep your sensitive data private.

The apps and code to do this are out in the wild, so this is not theoretical.

So… do the recommended.

How to do it:

https://www.java.com/en/download/help/disable_browser.xml

Source:

http://www.zdnet.com/homeland-security-warns-to-disable-java-amid-zero-day-flaw-7000009713/

172,022 views 78 replies
Reply #1 Top

I opted long ago to simply to remove Java totally as these exploits are too common.

Reply #2 Top

Quoting Neil, reply 1
I opted long ago to simply to remove Java totally as these exploits are too common.
End of Neil's quote

I removed anything Java on my S box since September. Haven't had the need for it since...I think there is a thread dedicated to this roaming around???

Reply #3 Top

Disabled in Firefox. Hopefully a fix is in the offing real soon.

Reply #4 Top

First of all thanks for the heads up. Second,  I got 2 questions:

1. Is this US only or worldwide?

2. If I delete java, what is an alternative software I should use, Im not really smart around computers, especially software stuff.

 

 

 

 

Reply #5 Top

thanks for the heads up.

edit** me either. no java control panel

Windows 7, Vista

  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter Java Control Panel.
  • Click on the Java icon to open the Java Control Panel.
Reply #6 Top

I just learned that I don't even have Java installed. Interesting.

Reply #7 Top

Quoting tito_defekt, reply 4
1. Is this US only or worldwide?

2. If I delete java, what is an alternative software I should use, Im not really smart around computers, especially software stuff.

End of tito_defekt's quote

1. The net is world wide... so...

2. You don't need Java.. except in some programs/applications. You know what programs you have, so check 'em out... if you have questions about them you can ask here or on the Forums where the software was obtained...

Reply #8 Top

Quoting kona0197, reply 6
I just learned that I don't even have Java installed. Interesting.
End of kona0197's quote

That's fine, kona... just make sure to disable Javascript in your browser.

Reply #9 Top

Quoting gmc2, reply 5
thanks for the heads up.

edit** me either. no java control panel

Windows 7, Vista


Click on the Start button and then click on the Control Panel option.
In the Control Panel Search enter Java Control Panel.
Click on the Java icon to open the Java Control Panel.
End of gmc2's quote

You're welcome...I don't either... just disable the sucker in your browser/s.

Reply #10 Top

For Firefox I an highly recommend the addon

 

NoScript

 

It allows you to state exactly what pages may use java, flash or scripts.

 

For example if you visit this the current page you are looking at.

 

Data is loaded from:

 

sinsofasolarempire.com

google.com

stardock.net

stardock.com

googleanalytics.com

twitter.com

facebook.net

 

Now, with no Script you can allow only the Java, Flash and scripts your really want to execute.

 

For me that means I tell NoScript to

 

Allow

sinsofasolarempire.com

google.com

stardock.net

stardock.com

 

 

Allow on this page only - normaly it is blocked but on this site it is not.

googleanalytics.com

 

Not trustworthy - those sites are always blocked wherever you surf.

twitter.com

facebook.net

 

 

Of course the decision what sites are allowed to do what is entirely yours.

 

I use it for several years now and never again had any browser hijacked.

Reply #11 Top

Quoting DrJBHL, reply 8

Quoting kona0197, reply 6I just learned that I don't even have Java installed. Interesting.

That's fine, kona... just make sure to disable Javascript in your browser.
End of DrJBHL's quote

 

Javascript ≠ Java ;)

Reply #12 Top

Quoting gmc2, reply 5
Windows 7, Vista

Click on the Start button and then click on the Control Panel option.

In the Control Panel Search enter Java Control Panel.

Click on the Java icon to open the Java Control Panel.
End of gmc2's quote

No Java Control Panel,,,what now?

Reply #13 Top

Quoting S, reply 12
No Java Control Panel,,,what now?
End of S's quote
If on Win7 look in Control Panel\Programs\Programs and Features and see if Java is installed. If it is, take whatever action you deem appropriate. If it isn't....carry on.

Reply #14 Top

Can it be uninstalled from the pc?

 

 

Opening the java control panel...I disabled java in the browser...but looking at that control panel, clicking on *Java* it says..."View and manage Java Runtime Versions and settings for Java applications and applets".    Then clicking on "View"... I see that  there is a *path* from the platform..etc. and it is "ENABLED" .  Should that also be disabled?

Reply #15 Top

Quoting teddybearcholla, reply 14
Can it be uninstalled from the pc?
End of teddybearcholla's quote
yes

Reply #16 Top

In add remove programs or I have Revo uninstaller....?  Thank you Xiandi!

Reply #17 Top

I left Javascript enabled. Facebook needs it. Besides I rarely visit sites outside of the 7 or 8 I visit everyday, all of witch are trusted sites.

Reply #18 Top

Quoting kona0197, reply 17
I left Javascript enabled. Facebook needs it.
End of kona0197's quote

Yes, but does anyone NEED Facebook?....;)

Reply #19 Top

I think you can leave JavaScript enabled, but I'd also use NoScript for further safety.  NoScript is only a problem if more than one person uses the computer and one or more don't understand how NoScript works - it can be very annoying and a source of friction.  In some cases that might be a feature rather than a bug, I'll admit.

I've found many of the sites I routinely use, particularly financial institution sites, require JavaScript be enabled.

Reply #20 Top

Quoting kona0197, reply 17
I left Javascript enabled. Facebook needs it.
End of kona0197's quote

Dunno about that one. I have zero [0] Java on my box and I'm able to view/see anything/all Facebook. I feel comfortable with my settings [Win 7 Pro]...

Reply #21 Top

Go into the options for Firefox and disable JavaScript. Facebook will have fits when you load it.

Reply #22 Top

Oh no how will I ever dial a nine-chevron address without Java?  :P

Reply #23 Top

I did it few days ago.. No problems with any website including Facebook.. Thank you very much for this hint! :)

Reply #24 Top

Oh no how will I ever dial a nine-chevron address without Java?
End of quote

Get Rodney to write a script...

Reply #25 Top

Quoting DrJBHL, reply 9

Quoting kona0197, reply 6I just learned that I don't even have Java installed. Interesting.

That's fine, kona... just make sure to disable Javascript in your browser.
End of DrJBHL's quote

 

... that's a joke, right? java and javascript have nothing to do with each other