Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In case anybody at FireEye reads this: is Windows XP the only OS vulnerable to this attack?


In addition to 7 which was already mentioned, Rapid7 says they've successfully tested it against Ubuntu 10.04 and OSX 10.7.4 as well.

https://community.rapid7.com/community/metasploit/blog/2012/...

Errata Sec claims it's working on a fully-patched Ubuntu 12.04, provided you're using the official Java package instead of the default OpenJRE. OSX 10.8.1 has also been confirmed.

http://erratasec.blogspot.com/2012/08/new-java-0day.html


I'm not from FireEye, but XP is not the only OS vulnerable. Rapid7 has created an exploit for Metasploit and was able to successfully execute an attack against a fully patched Windows 7 SP1 with Java 7 Update 6.

http://www.securityweek.com/new-java-exploit-spotted-wild




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: