Skip to: Site Navigation | Search | Content

Legit Reviews

Product Reviews - Industry Facts - Technology Issues

Legit News

New Java Zero-Day Exploit Kit Peddled for 5 Grand

Only three days ago on Sunday, Oracle patched yet another major zero-day security flaw in Java. The company isn't known for being keen on patching software vulnerabilities in its Java software and usually takes its time, but this one was so serious that they issued one very quickly and not according to any usual time schedule. In fact, the US Department of Homeland Security recommended that the software be disabled unless it was "absolutely necessary" to use it. Even after the patch was issued, the same advice was repeated on Monday by the department's Computer Emergency Readiness Team (US-CERT).

java250
This time however, an even worse zero-day flaw has been uncovered which very few people know about. This makes it much more dangerous, since the window of opportunity for exploitation is bigger. Security blogger Brian Krebs, discovered this new flaw by visiting an exclusive cybercrime forum where since Monday (Jan 14th) an exploit kit was being peddled by the site's admin for a staggering $5,000 to two lucky buyers - who were even invited to outbid each other! This exploit is present in the latest version of Java (v7 update 11) and crucially, not in any previous exploit kit, thereby allowing the seller to command a high price for it. His sales pitch is quoted below and it appears that the site's admin has since found a second buyer, because the thread has now been deleted.

 

The exploit kit works in the usual way through web browser vulnerabilities, exposed when Java is installed on the target's computer. So, the advice remains to uninstall Java from your computer - no one should be under the illusion that their computer is safe with this security hole-riddled software on it.

New Java 0day, selling to 2 people, 5k$ per person

And you thought Java had epically failed when the last 0day came out.

I lol'd. The best part is even-though java has failed once again and let users get compromised… guess what? I think you know what I'm going to say… there is yet another vulnerability in the latest version of java 7. I will not go into any details except with seriously interested buyers.

Code will be sold twice (it has been sold once already). It is not present in any known exploit pack including that very private version of [Blackhole] going for 10$k/month. I will accepting counter bids if you wish to outbid the competition. What you get? Unencrypted source files to the exploit (so you can have recrypted as necessary, I would warn you to be cautious who you allow to encrypt… they might try to steal a copy) Encrypted, weaponized version, simply modify the url in the php page that calls up the jar to your own executable url and you are set. You may pm me.

Posted by | Wed, Jan 16, 2013 - 10:45 PM


blog comments powered by Disqus

Recent Articles
  • LightDims LED Dimming Sticker Review
  • Gigabyte GeForce GTX 770 WindForce 3X 2GB Video Card Review
  • The 50 Best Booth Babes of E3 2013
  • What Enabling C6/C7 Low-Power States Do on the Core i7-4770K Haswell CPU
  • ASUS RT-AC66U 802.11ac Wireless-AC1750 Router Review
  • Mad Catz R.A.T. M and M.O.U.S. 9 Gaming Mice Review
  • E3 2013: Day 0 - What to Expect from This Year's E3 Expo
  • PowerColor Radeon HD 7850 SCS3 1GB Passive Video Card Review
  • Corsair Voyager Air Wireless Mobile Drive Review
  • NVIDIA GeForce GTX 770 Reviewed in 2-Way SLI and NVIDIA Surround
Recent News
  • Samsung to Give Away 1 Million Copies of Jay-Z’s New Album
  • Intel Haswell-E Halo Platform Will Have 8-Cores, DDR4, X99 Chipset and More
  • SteelSeries H-Series Gaming Headsets @ E3 2013
  • Intel Desktop Processor and Chipset Roadmap Leaked For 2013 and 2014
  • Samsung Galaxy S 4 Active Coming To AT&T On June 21st For $199
  • Snoop Lion Lets The Bass Go for DreamWorks' Turbo @ E3 2013!
  • Alienware 14 Gaming Laptop Sneak Peek @ E3 2013
  • Razer Shows Off New Blade Gaming Notebook @ E3
  • Legit Reviews Takes a First-Look at NVIDIA's SHIELD at E3 2013
  • NVIDIA Shows Legit Reviews The GeForce GTX 780 at E3 2013

Socialize

  • Facebook
  • Twitter
  • YouTube

Search

Hot Topics

  • LightDims LED Dimming Sticker Review
  • 2TB WD Elements External USB Hard Drive For $70 Shipped
  • Gigabyte GeForce GTX 770 WindForce 3X 2GB Video Card Review
  • ThinkPad predicament
  • The 50 Best Booth Babes of E3 2013
  • What Enabling C6/C7 Low-Power States Do on the Core i7-4770K
  • BIWIN Introduces Industrial Grade Disk-On-Modules
  • Samsung Mobile and AT&T Announce Samsung Galaxy S 4 Active
  • ASUS RT-AC66U 802.11ac Wireless-AC1750 Router Review
  • DreamWorks Animation Makes Mobile History With the Turbo App

Explore ::

  • News
  • Articles
  • Editorial
  • Interviews
  • Events
  • Folding
  • Forums

Content ::

  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • Bluetooth
  • Cooling
  • Miscellaneous

About ::

  • Contact
  • About Us
  • Disclaimer

Copyright © 2002-2013 Legit Reviews™ & LegitReviews.com - All Rights Reserved.

  • Home
  • Forums
  • Favorite
  • RSS Feeds
  • Shopping
  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • PC Cases
  • Cooling
  • Misc