Only five days after Google researcher to reveal information about Java error hasn’t been patched, shown to attack exploiting this vulnerability. Researcher Tavis Ormandy of Google has give details of public Java vulnerability to security mailing list Full-Disclosure. According to Mr. Ormandy, all versions of Java for Windows are "sticky" error. The other OS running Java is not affected.
Mr. Roger Thompson, research director of antivirus maker said AVG Technologies, web lyrics Songlyrics.com accidentally redirected users to a server containing the attack code to exploit the vulnerability by Mr. Ormandy detection, "inject" malicious code for the victims. Songlyrics.com page provided to the song lyrics of singers like Lady Gaga, Rihanna, Usher and Miley Cyrus. It seems that contains an iFrame Songlyrics.com transfer visitors to access the site "poison", where users will be attacked.
Windows users running Internet Explorer (IE) from Microsoft and Mozilla's Firefox will be in danger if they install the Java browser plug-ins. Chrome seems to be safe, but I'm not sure, Mr. Thompson said.



Reply With Quote
Copyright Techfuels
Bookmarks