Topic: Java is in fact the devil.

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,974
http://www.cisco.com/web/offers/lp/2014-annual-security-report/index.html

tl;dr :Cisco 2014 Annual Security Report says 91% of web exploits target Java.


Posted: February 03, 2014, 09:45:42 am

Offline Apostrophe Spacemonkey

  • Fuck this title in particular.

  • Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!
  • Posts: 19,050
I agree/disagree (delete one) with the above statement.

Reply #1 Posted: February 03, 2014, 12:35:50 pm

Offline Xenolightning

  • Moderator
  • Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!
  • Posts: 3,485
http://www.cisco.com/web/offers/lp/2014-annual-security-report/index.html

tl;dr :Cisco 2014 Annual Security Report says 91% of web exploits target Java.

TLDR;

But do "they" only TARGET Java and not AFFECT Java? Targeting and actually doing anything malicious, are two different things.

Reply #2 Posted: February 03, 2014, 06:03:08 pm
-= Sad pug is sad =-

Codex

  • Guest
TLDR;

But do "they" only TARGET Java and not AFFECT Java? Targeting and actually doing anything malicious, are two different things.
Java fanboy detected

Reply #3 Posted: February 03, 2014, 06:04:16 pm

Offline Xenolightning

  • Moderator
  • Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!
  • Posts: 3,485
TLDR;

But do "they" only TARGET Java and not AFFECT Java? Targeting and actually doing anything malicious, are two different things.
Java fanboy detected
OH GOD NO, quite the opposite.

But I detect potential marketing rubbish pretty quickly :)

Reply #4 Posted: February 03, 2014, 06:07:02 pm
-= Sad pug is sad =-

Codex

  • Guest
OH GOD NO, quite the opposite.

But I detect potential marketing rubbish pretty quickly :)
Java fanboy imminent

Reply #5 Posted: February 03, 2014, 08:13:36 pm

Offline Apostrophe Spacemonkey

  • Fuck this title in particular.

  • Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!
  • Posts: 19,050
Tiwa incoming in 3... 2... 1...

Reply #6 Posted: February 04, 2014, 08:24:24 am

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,974
But do "they" only TARGET Java and not AFFECT Java? Targeting and actually doing anything malicious, are two different things.

In short, 91% of infected PC's monitored were compromised via Java vulnerabilities.



Reply #7 Posted: February 04, 2014, 09:39:35 am

Offline Xenolightning

  • Moderator
  • Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!
  • Posts: 3,485
But do "they" only TARGET Java and not AFFECT Java? Targeting and actually doing anything malicious, are two different things.

In short, 91% of infected PC's monitored were compromised via Java vulnerabilities.
TROOLOLLOLOLO.

Any numbers on what versions?

Reply #8 Posted: February 04, 2014, 11:09:47 am
-= Sad pug is sad =-

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,974
But do "they" only TARGET Java and not AFFECT Java? Targeting and actually doing anything malicious, are two different things.

In short, 91% of infected PC's monitored were compromised via Java vulnerabilities.
TROOLOLLOLOLO.

Any numbers on what versions?

No hard numbers, other than "However, Cisco TRAC/SIO research also shows that 76 percent of enterprises using Cisco solutions are also using the Java 6 Runtime Environment, in addition to Java 7" and goes off on a big long rant on why people who still have the Java 6 JRE installed are babykilling spawns of satan.

Also at it's peak last year Java Malware made up 14% of all malware on the entire internets.

Reply #9 Posted: February 04, 2014, 11:42:45 am

Offline Apostrophe Spacemonkey

  • Fuck this title in particular.

  • Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!
  • Posts: 19,050
No hard numbers, other than "However, Cisco TRAC/SIO research also shows that 76 percent of enterprises using Cisco solutions are also using the Java 6 Runtime Environment, in addition to Java 7" and goes off on a big long rant on why people who still have the Java 6 JRE installed are babykilling spawns of satan.


A better option to updating Java from 6 to 7 is to just uninstall Java completely.

Reply #10 Posted: February 04, 2014, 11:56:16 am

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,974
A better option to updating Java from 6 to 7 is to just uninstall Java completely.

Shut up and have my babies?

Reply #11 Posted: February 04, 2014, 12:00:15 pm

Offline Tiwaking!

  • Hero Member
  • Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!
  • Posts: 12,562
No hard numbers, other than "However, Cisco TRAC/SIO research also shows that 76 percent of enterprises using Cisco solutions are also using the Java 6 Runtime Environment, in addition to Java 7" and goes off on a big long rant on why people who still have the Java 6 JRE installed are babykilling spawns of satan.

Also at it's peak last year Java Malware made up 14% of all malware on the entire internets.
Why would someone still be using Java 6 Runtime Environment? Their network administrators shouldnt be allowed near computers

Reply #12 Posted: February 04, 2014, 12:06:08 pm
I am now banned from GetSome

Offline Xenolightning

  • Moderator
  • Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!Xenolightning is awe-inspiring!
  • Posts: 3,485
Yeah, the joys of large Enterprise Systems that use environment specific functions cause upgrades to be horrendously painful, and require a large amount of redevelopment.

Muppets. Use version indifferent functions! :B

Reply #13 Posted: February 04, 2014, 12:32:34 pm
-= Sad pug is sad =-

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,974
Why would someone still be using Java 6 Runtime Environment? Their network administrators shouldnt be allowed near computers

Nothing to do with network admins.. I can hand on heart say that if most sysadmins had their way,  the Java JRE and any app that required it would be banned. But sadly business needs etc.

It's to do with software devs writing shitty apps, that are hardcoded to use specific versions of Java, or that forcibly install said versions of java during install, etc. Same thing happens to a degree with Flash, Quicktime, etc but Java is the worst offender by far.

Pretty much every software dev should write their apps, and package their installers in such a way that everything can be installed silently, all options can be configured silently, all pre-reqs can be overwritten, and uninstalls are also silent and clean. But no the world is full of retard devs, who make life living hell for app packager and sys admins everywhere.





Reply #14 Posted: February 04, 2014, 03:20:03 pm

Offline RightHandOnly

  • Just settled in
  • RightHandOnly has no influence.
  • Posts: 876
java is painful and the newer versions now expire as well...forcing you to update....for security reasons, so watch out if you are installing new versions

Unfortunately many 3rd party vendors including cisco require certain versions of Java to run the GUI's to admin their devices...for exmaple cisco PIX and cisco ASA.

you update the version of java the PIX admin tool uses and you wont be able to get in....

its not new that java is the big threat..it has been for ages.

Reply #15 Posted: February 04, 2014, 07:31:02 pm
With Age comes Wisdom and Skill.......I have all 3.


                                                           




                                                                                       I\'m so Leet , I d

Offline Lias

  • Administrator
  • Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!Lias is awe-inspiring!
  • Posts: 3,974
java is painful and the newer versions now expire as well...forcing you to update....for security reasons, so watch out if you are installing new versions

Unfortunately many 3rd party vendors including cisco require certain versions of Java to run the GUI's to admin their devices...for exmaple cisco PIX and cisco ASA.

you update the version of java the PIX admin tool uses and you wont be able to get in....

its not new that java is the big threat..it has been for ages.

Cisco make some truly truly shite software. Had to package Cisco Configuration Professional recently.. jesus wept at having to build Auto-IT scripts to install software from a major vendor like Cisco.

I swear app packaging makes me nearly as grumpy as Helldesk did many years ago when your constantly bombarded with poorly written apps.








Reply #16 Posted: February 04, 2014, 08:45:39 pm

Offline Craigor

  • Administrator
  • Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!Craigor is awe-inspiring!
  • Posts: 11,465
I swear app packaging makes me nearly as grumpy as Helldesk did many years ago when your constantly bombarded with poorly written apps.


^ I feel your pain.

Reply #17 Posted: February 04, 2014, 09:38:32 pm
<a href="steam://friends/add/76561197966242864/">Add me to Steam</a> <- Fixed! lol

Offline Ping

  • Devoted Member
  • Ping has no influence.
  • Posts: 1,405
No hard numbers, other than "However, Cisco TRAC/SIO research also shows that 76 percent of enterprises using Cisco solutions are also using the Java 6 Runtime Environment, in addition to Java 7" and goes off on a big long rant on why people who still have the Java 6 JRE installed are babykilling spawns of satan.

Also at it's peak last year Java Malware made up 14% of all malware on the entire internets.
Why would someone still be using Java 6 Runtime Environment? Their network administrators shouldnt be allowed near computers


Because you have crappy old applications/hardware that break unless you use an older version of Java... e.g. for me, SDM software for Cisco [ironic this is a Cisco article] ASA Firewalls (my case can be solved with an update, but that's not the point... sometimes it's impossible to upgrade).


For me best practice is to not install Java unless you need it... If you "do" need to run an old version then only run it on locked environment. I think more browsers should take the stance that Apple took, if Java isn't used within "X" days, the browser plugin is disabled.


Java can be very powerful, I cut my teeth on it... but its also a pain in the ass. I agree with OP for the most Part

Reply #18 Posted: February 04, 2014, 11:16:00 pm



Offline RightHandOnly

  • Just settled in
  • RightHandOnly has no influence.
  • Posts: 876
java is painful and the newer versions now expire as well...forcing you to update....for security reasons, so watch out if you are installing new versions

Unfortunately many 3rd party vendors including cisco require certain versions of Java to run the GUI's to admin their devices...for exmaple cisco PIX and cisco ASA.

you update the version of java the PIX admin tool uses and you wont be able to get in....

its not new that java is the big threat..it has been for ages.

Cisco make some truly truly shite software. Had to package Cisco Configuration Professional recently.. jesus wept at having to build Auto-IT scripts to install software from a major vendor like Cisco.

I swear app packaging makes me nearly as grumpy as Helldesk did many years ago when your constantly bombarded with poorly written apps.


aaarrggh...Autoit...when everything else has failed....used Autoit to script Orcale financila Apps for a large coampany...so funny watching mouse move around screen...lol

Reply #19 Posted: February 06, 2014, 05:16:44 pm
With Age comes Wisdom and Skill.......I have all 3.


                                                           




                                                                                       I\'m so Leet , I d

Offline Growler

  • Hero Member
  • Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!Growler is awe-inspiring!
  • Posts: 14,590
hey guys, where can i download Java 6 runtime environment?

Reply #20 Posted: February 06, 2014, 06:48:29 pm
Think of me like Yoda,
but instead of being little and green,
I wear suits and I'm awesome.
I'm your bro - I'm Broda!

Offline Apostrophe Spacemonkey

  • Fuck this title in particular.

  • Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!Apostrophe Spacemonkey is awe-inspiring!
  • Posts: 19,050
hey guys, where can i download Java 6 runtime environment?

In hell.

Reply #21 Posted: February 07, 2014, 08:47:23 am

Offline RightHandOnly

  • Just settled in
  • RightHandOnly has no influence.
  • Posts: 876
sorry G, thought I had it in my old packaged apps but I dont sorry

Reply #22 Posted: February 07, 2014, 09:01:59 am
With Age comes Wisdom and Skill.......I have all 3.


                                                           




                                                                                       I\'m so Leet , I d

Offline Tiwaking!

  • Hero Member
  • Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!Tiwaking! is awe-inspiring!
  • Posts: 12,562
hey guys, where can i download Java 6 runtime environment?
I have it, but you better be bloody joking me

I made a midi keyboard in Java but for some reason, some undocumented and unknown reason the last Java Runtime Environment that supports it is 6_0_23. The error it throws is "Yeah, Nah" "Mark Not Supported for I/O Type". And there is nothing anywhere about it. And its a bullshit error anyway because it works perfectly fine before 6_0_24

The very last Java 6 update is:
jre-6u45-windows-i586

Reply #23 Posted: February 07, 2014, 09:32:07 am
I am now banned from GetSome

Offline Pyromanik

  • Hero Member
  • Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!Pyromanik is awe-inspiring!
  • Posts: 28,834
It worries me how prolific it is, and no one cares. Like when you visit a BANK's website and

Error 500: java.lang.NullPointerException

Reply #24 Posted: February 09, 2014, 08:09:47 am
Everyone needs more Bruce Campbell.