New year, new Java zeroday!

Does anybody know somthing about this?
http://labs.alienvault.com/labs/index.php/2013/new-year-new-java-zeroday/
Earlier this morning @Kafeine alerted us about a new Java zeroday being exploited in the wild. With the files we were able to obtain we reproduced the exploit in a fully patched new installation of Java. As you can see below we tricked the malicious Java applet to execute the calc.exe in our lab.bye
TPD

Jim Henderson wrote:
> On Wed, 19 Mar 2014 23:39:03 +0000, Preferred User wrote:
>
>> Jim Henderson wrote:
>>
>>> On Mon, 13 Jan 2014 15:17:22 +0000, Bob Crandell wrote:
>>>
>>>
>>> Terminal services or Citrix would solve the latter issue. For the
>>> first issue, that sounds like a process issue rather than a technology
>>> issue.
>>>
>>> Jim
>>>
>> Ok. With this solution, can he who is running Firefox slide it over to
>> her who is using Calc and drag her Calc over to his desktop? He would
>> then finish the inventory report while she is playing online poker.
>>
>> This would work?
>
> Probably not, because it's not a share desktop amongst all users - you
> end up with very poor security with a single shared desktop.
>
> But I know that in hospitals, this type of solution is sometimes used so
> a user's desktop can be moved from room to room. The most recent
> experience I had in a hospital ER (a couple weeks ago), I noticed it was
> VMware Infrastructure.
>
> Jim
>
In this case it is a dentist office. The users are sitting next to each
other. Looks like to make this work they will need a combination of MDM and
VMware.
Oh well. The hunt goes on. I wonder just how badly he really wants this

Similar Messages

  • New Year, new problems

    Well, not really new problems - more like same old.  So after months of fighting to get my speed back up and then begrudgingly accepting around 40Mb/s for a while (42 on a good day) - for the past few weeks, I've been back down to 30Mb.
    As if going from 50+ to 20 then slowly back up to 40 (and being told it won't get better than that...) was not reasonable enough on my part - this is getting painful now.  How much of my contract do I have to spend on lower speeds and fighting to getsome thing slightly better?
    BT dealt with my issues and got the speed increased - it was not what I expected or wanted, but it was better.  This has only lasted a few weeks and now it looks like I will have to go through more pain for goodness knows how long.  It seems a shame that they allow this poor level of service - after months of pain, something was done and perhaps I felt less strongly about jumping ship to a more reliable provider, but if I just go through a few cycles of this pain, my contract will be up and I think I will be once bitten, twice shy...
    Crappy New Year!

    samsonite wrote:
    Well, not really new problems - more like same old.  So after months of fighting to get my speed back up and then begrudgingly accepting around 40Mb/s for a while (42 on a good day) - for the past few weeks, I've been back down to 30Mb.
    As if going from 50+ to 20 then slowly back up to 40 (and being told it won't get better than that...) was not reasonable enough on my part - this is getting painful now.  How much of my contract do I have to spend on lower speeds and fighting to getsome thing slightly better?
    BT dealt with my issues and got the speed increased - it was not what I expected or wanted, but it was better.  This has only lasted a few weeks and now it looks like I will have to go through more pain for goodness knows how long.  It seems a shame that they allow this poor level of service - after months of pain, something was done and perhaps I felt less strongly about jumping ship to a more reliable provider, but if I just go through a few cycles of this pain, my contract will be up and I think I will be once bitten, twice shy...
    Crappy New Year!
    First, this is why BT advertise Infinity as an Upto product.
    Second, if there are problems with your line, then your speed may be reduced until your problem is fixed and then speed may return, but as sometimes physical cable is replaced to solve the problems with the line it is not always possible to get your orginal speed back.

  • New Year, New Challenge

    Happy New Year Y'All.
    With a new year comes a new challenge.
    Parts list:
    1 Computer with Windows 7 pro
    2 Monitors
    2 Keyboards
    2 Mice
    2 Users
    Goal:
    Each user to use some random Wondows program independantly with the added
    ability to transfer control of at leasst one of the programs to the other
    user.
    One of my clients brought this to me last week. I know there has been talk
    about doing this kind of thing over the years. Are we any closer to being
    able to being able to have 2 users work in 2 different programs on the same
    computer independantly?
    Gat run
    Bob

    Jim Henderson wrote:
    > On Wed, 19 Mar 2014 23:39:03 +0000, Preferred User wrote:
    >
    >> Jim Henderson wrote:
    >>
    >>> On Mon, 13 Jan 2014 15:17:22 +0000, Bob Crandell wrote:
    >>>
    >>>
    >>> Terminal services or Citrix would solve the latter issue. For the
    >>> first issue, that sounds like a process issue rather than a technology
    >>> issue.
    >>>
    >>> Jim
    >>>
    >> Ok. With this solution, can he who is running Firefox slide it over to
    >> her who is using Calc and drag her Calc over to his desktop? He would
    >> then finish the inventory report while she is playing online poker.
    >>
    >> This would work?
    >
    > Probably not, because it's not a share desktop amongst all users - you
    > end up with very poor security with a single shared desktop.
    >
    > But I know that in hospitals, this type of solution is sometimes used so
    > a user's desktop can be moved from room to room. The most recent
    > experience I had in a hospital ER (a couple weeks ago), I noticed it was
    > VMware Infrastructure.
    >
    > Jim
    >
    In this case it is a dentist office. The users are sitting next to each
    other. Looks like to make this work they will need a combination of MDM and
    VMware.
    Oh well. The hunt goes on. I wonder just how badly he really wants this

  • New year - new desaster: Version Cue CS4 damaged all my december work files

    This year has not a good start for me. Now holidays are over and i have to work further on my projects from december. But now all files in my version cue projects from december are away - only the folder structure is still there, but where are the files. I installed the last version 4.01, i have looked in the project trash can ... nothing! Terrible!!!
    About my system: i installed CS4 Web Standard, end of November on my Vista Home PC. PC works fine and has no harddisk problems. I suppose, that my failure was, that i installed Dreamweaver CS4 new in the end of December - not the other components only a re-install of Dreamweaver. After that i rekognized that my virtual drive from version cue was'nt active, but i got it back with all projects in it, but most files are away now.
    Are the files really away, or is there a chance to get them back? Please Adobe guys, don't say no!
    Shocked Greetings
    Heiner

    It says 'no items matched the search'.
    I looked in the adobe common folder and cant find the versioncue file there either....
    Found a workaround for the copy/paste and deleting problems though. I keep my usb drive plugged in and the window open on my computer, whatever needs copying gets dragged in there and dragged back out. Then I drag the file in the usb into the recycle bin. Kind of a time consuming process(for larger files) but I hope it helps anyone with the problem.

  • New year, new kid in town

    Hi, New kid in town here just waiting for my first Apple server X within the next days,
    sincerely I´ve no idea how to manage such machine, but I have a lot of courage ( je, je ) and a couple of clear things:
    1- I need it for distribute and sell my pictures to my current clients and the new ones I´ll get all around the world,
    2- I like challenges, I hope a little help from your huge wisdom.
    but for now just let me say hello and wish all of you a very, very happy new 2006 year.
    PD- I posted this message three times, but unable to see it, so, my apologies if it appears ...three times.
    G5   Mac OS X (10.4.3)   is anybody out there?
    G5   Mac OS X (10.4.3)  

    Hi,
    I think system is confused due to the fact, that you are closing year, which is beyond the current calendar year.
    Regards,
    Eli

  • I have a dream : New Year SAP Hopes

    Next Year,
    I hope that when I download a PDF file from service.sap.com, it wil not be called aefbcedf51dc6aEN.pdf.
    I hope that When I download a support package from service.sap.com, the file name will have a meaningful name.
    I hope that I will not spend days to find out where to download a specific support package.
    I hope that I will use J2EE log files whose Lines length will fit my screen size.
    I hope that I will get meaningfull Java Error messages.
    I hope that I will find in the installation guides the DVD numbers to download.
    I hope that I will not have to upgrade or patch SOLMAN each time I have to use it.
    I hope that I will not discover that when I upgrade SRM, my company has to redo all the specific changes.
    I hope that I will not discover that applying an ECC6 EHP is in fact a hidden release upgrade.
    I hope that The Netweaver Java stack will start as fast as the Netweaver Abap stack.
    I hope that service.sap.com will not ask me to send my client certificate, 30 times per session.
    I hope that service.sap.com will be stable and fast.
    I hope that SDN forums will not crash.
    I hope that Microsoft Office patches will not destroy SAP BEX each time.
    I hope that there will be no more dual stack based SAP products.
    I hope that SAP developpers will make their choice between Abap or JAva Webdynpro.
    I hope that the SAP Software products TCO will stop to increase.
    I hope that SAP developpers will finally understand ergonomy from an end user point of view.
    I hope that non Unicode ECC6 will be able to display the Euro Symbol.
    I hope that there will be a real SAP ESS installation guide.
    I hope that I will not need to use 3 or 4 different UI technologies to administrate PI.
    I hope that SDN users will do their own research before asking basic questions already answered many times.
    I hope that All European SAP jobs will not be offshored.
    I hope that SAP support will not bounce my message with the note I just told them is not applicable in my system.
    And finally...
    I hope that I will still enjoy my job as a SAP admin as I did this year !
    (even if I like to rant...)
    Happy New Year to all (for the same !)
    Olivier

    Adding one more wish;
    SAP will give limited(display) access to search customer messages on service market place for all customers(search messages)
    Regards
    Nick Loy

  • When is the new version of java coming out?

    Hi! When is everyone like, starting to use the new version of java? I want to know because my teacher said that we have to learn it! I was like, whatever! Java is totally hard enough with loads of new stuff! Can any of you ppl tell me the date?
    Thanx!
    JS

    I can't wait for 2.0, it will actually do the
    programming by itself.3.0 will not only do the then-current programming tasks by itself, it will go backward in time and do all previous years' homework assignments, obfuscate the .class files, create .exes out of them, and cause all questions about them (even though those questions are no longer needed, nor even exist any more) to be clear and specific. Then it will undelete the watercooler.

  • Happy New Year!   Chinese new year!!!!!!

    Today is the first day of Chinese lunar-calendar new year.
    I bless people all over the world happy and felicity.
    bless Java World getting more and more flourish!!
    maybe this's not a technologic topic, it's only my sincerely bless.
    but as Chinese tradition it's very propitious.
    i'm sorry for my English. : )

    maybe this's not a technologic topicDon't let that worry you, and we won't let itworry
    us. Happy New Year.Indeed. Only andrew minter is perturbed by posts
    lacking technologic content.
    I am perturbed by post that lack Technotronic
    content; I would beseech you to pump up the
    jam.what about Electronic content? maybe he should tighten up

  • Multiple libraries, projects and reorganizing for the new year

    I have used Aperture since 1.0 and really like it but the growing pains are still present - over time of use, I've ended up with multiple libraries [2 main ones and 2-3 little ones that probably can be safely archived]. I want to start fresh in the new year and have a new Library that is my main one, my only one in fact == is it possible/feasible/desireable to export projects from Library A and B and then import the ones i want into my 2007 Library the way my new organizing system will be? I mainly have images according to geography and people [e.g. people in locations versus family and friends]. Can I consolidate all my Libraries into one new one for use in the future ?? Will exporting each project and then importing into my new master Library work??

    I've been thinking just a little about what features I would like the next rev of aperture to have. Though I haven't thought through the specifics, easier and more efficient use and management of multiple libraries, projects etc would be nice. Whole aperture projects referenced from multiple libraries or some such? (I said I hadn't thought it through!)
    It's over a year since aperture came out, macworld is coming up, and I suspect that 2.0 will be released eventually some time in the future, perhaps with changes (maybe even improvements!) in library and project workflow.
    So while I too am considering how to organize my own aperture materials I am currently holding off for bit just in case there might maybe possibly be (Conjecture Warning!!!) something new announced soon....
    MBP17 2.16 ghz 2gb 120gb   Mac OS X (10.4.8)  
    MBP17 2.16 ghz 2gb 120gb   Mac OS X (10.4.8)  

  • How do I move an account to the top of the column of accounts? I have version 31.3. Thanks for any help you can offer and Happy New Year!

    I see that my Thunderbird account listings (in the leftmost column) are alphabetical. I want to move the bottom listing to the top. Is this possible? I'm using Windows 7. Oh, and did I mention Happy New Year?

    Try this add-on:
    https://addons.mozilla.org/en-US/thunderbird/addon/manually-sort-folders/
    http://www.ramsden.org.uk/3_How_to_install_Add-ons_in_Thunderbird.html

  • How to change the year in a range of column dates to the new year?

    How to change the year in a range of column dates to the new year?

    Depends on the pattern of the dates. The last procedure will work for any pattern, or no pattern at all.
    For examples.the dates are assumed to be in column A, starting at A2
    Sequential dates?
    Enter first updated date in the first cell.
    Enter =A2+1 in cell A3. Copy the cell.
    Select A3 to the end of the list. Paste.
    With the cells still selected, Copy, then go Edit > Paste Values.
    Evenly spaced dates?
    Same procedure as above, but replace +1 in the formula with + and the number of days between dates in the list.
    Randomly spaced dates?
    Select cell B2. Press option-left arrow to insert a (temporary) column to the left of column B.
    Click on the empty cell B2 in the new column. Enter the formula below:
    =DATE(YEAR(A)+1,MONTH(A),DAY(A))
    Copy the cell, then select B2 - Bn where n is the last ow containing a date to be converted. Paste,
    With the cells still selected, Copy.
    Click on A2, then go Edit > Paste values.
    Click on the column B reference tab to select all of column B.
    Hover the mouse over the right end of the reference tab, and click the black triangle when it appears.
    Choose Delete Column from the menu that appears.
    Regards,
    Barry

  • HT2523 How do I add shadow to the title of a document while in Pages? For instance: NEW YEAR'S NEEDS. I'm also at a loss to know how to create a folder for certain types of documents such as "Sermons" or "Lessons."

    How do I add shadow to a title, such as, NEW YEAR'S NEEDS, while in Pages? I also don't know how to set a new folder for documents of the same type such as, "Sermons," or "Lessons." Any help will be greatly appreciated.
    Donnie

    Yes, I very well may be over thinking this, but I tried duplicating and moving it, but the text distorts slightly, which can be mostly remedied by rotating it on the x-axis, although the light is still off. And the shadows and reflections are not visible - this is pic1... In pic2, I used "rotate 3d object" with the green and red arrows,  instead of just sliding it up the y-axis using the coordinates in the scene tab. Using the green and red arrows to move the text preserved the reflections but the shadows now aren't visible. It was also hard to align the text perfectly in scenario 2. Thanks for the help

  • A New Year, a New Challenge! Become the FIRST WPF Guru of 2015!

    Happy New Year!
    "Guru 2014" is so 'last year'!
    The real glory is to be the first Guru of 2015! :D
    The birth of a new year, and a new hero?
    Or the stamp of authority from long established Guru leaders?
    The challenge is on, all eyes are watching, anyone could win this month.
    The prize? Glory! Honor! Virtual medals! Unashamed love and worship from those within the community and those bloging about it (article spotlights,
    weekly awards).
    Published interviews and the chance to climb the TechNet social ladder. Become a true TNWiki Ninja and
    advance through to black belt... and beyond!
    All you have to do is add an article to TechNet Wiki from your own specialist field. Something that fits into one of the categories listed on the submissions page. Copy in your own blog posts, a forum solution, a white paper, or just something
    you had to solve for your own day's work today.
    Drop us some nifty knowledge, or superb snippets, and become MICROSOFT TECHNOLOGY GURU OF THE MONTH!
    This is an official Microsoft TechNet recognition, where people such as yourselves can truly get noticed!
    HOW TO WIN
    1) Please copy over your Microsoft technical solutions and revelations to
    TechNet Wiki.
    2) Add a link to it on
    THIS WIKI COMPETITION PAGE (so we know you've contributed)
    3) Every month, we will highlight your contributions, and select a "Guru of the Month" in each technology.
    If you win, we will sing your praises in blogs and forums, similar to the
    weekly contributor awards. Once "on our radar" and making your mark, you will probably be
    interviewed for your greatness, and maybe eventually even invited into other inner TechNet/MSDN circles!
    Winning this award in your favoured technology will help us learn the active members in each community.
    Feel free to ask any questions below.
    More about TechNet Guru Awards
    Thanks in advance!
    Pete Laker
    #PEJL
    Got any nice code? If you invest time in coding an elegant, novel or impressive answer on MSDN forums, why not copy it over to
    TechNet Wiki, for future generations to benefit from! You'll never get archived again, and
    you could win weekly awards!
    Have you got what it takes o become this month's
    TechNet Technical Guru? Join a long list of well known community big hitters, show your knowledge and prowess in your favoured technologies!

    Happy New Year;)
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • A New Year, a New Challenge! Become the FIRST Visio Guru of 2015!

    Happy New Year!
    "Guru 2014" is so 'last year'!
    The real glory is to be the first Guru of 2015! :D
    The birth of a new year, and a new hero?
    Or the stamp of authority from long established Guru leaders?
    The challenge is on, all eyes are watching, anyone could win this month.
    The prize? Glory! Honor! Virtual medals! Unashamed love and worship from those within the community and those bloging about it (article spotlights,
    weekly awards).
    Published interviews and the chance to climb the TechNet social ladder. Become a true TNWiki Ninja and
    advance through to black belt... and beyond!
    All you have to do is add an article to TechNet Wiki from your own specialist field. Something that fits into one of the categories listed on the submissions page. Copy in your own blog posts, a forum solution, a white paper, or just something
    you had to solve for your own day's work today.
    Drop us some nifty knowledge, or superb snippets, and become MICROSOFT TECHNOLOGY GURU OF THE MONTH!
    This is an official Microsoft TechNet recognition, where people such as yourselves can truly get noticed!
    HOW TO WIN
    1) Please copy over your Microsoft technical solutions and revelations to
    TechNet Wiki.
    2) Add a link to it on
    THIS WIKI COMPETITION PAGE (so we know you've contributed)
    3) Every month, we will highlight your contributions, and select a "Guru of the Month" in each technology.
    If you win, we will sing your praises in blogs and forums, similar to the
    weekly contributor awards. Once "on our radar" and making your mark, you will probably be
    interviewed for your greatness, and maybe eventually even invited into other inner TechNet/MSDN circles!
    Winning this award in your favoured technology will help us learn the active members in each community.
    Feel free to ask any questions below.
    More about TechNet Guru Awards
    Thanks in advance!
    Pete Laker
    #PEJL
    Got any nice code? If you invest time in coding an elegant, novel or impressive answer on MSDN forums, why not copy it over to
    TechNet Wiki, for future generations to benefit from! You'll never get archived again, and
    you could win weekly awards!
    Have you got what it takes o become this month's
    TechNet Technical Guru? Join a long list of well known community big hitters, show your knowledge and prowess in your favoured technologies!

    Happy New Year!
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • A New Year, a New Challenge! Become the FIRST FIM Guru of 2015!

    Happy New Year!
    "Guru 2014" is so 'last year'!
    The real glory is to be the first Guru of 2015! :D
    The birth of a new year, and a new hero?
    Or the stamp of authority from long established Guru leaders?
    The challenge is on, all eyes are watching, anyone could win this month.
    The prize? Glory! Honor! Virtual medals! Unashamed love and worship from those within the community and those bloging about it (article spotlights,
    weekly awards).
    Published interviews and the chance to climb the TechNet social ladder. Become a true TNWiki Ninja and
    advance through to black belt... and beyond!
    All you have to do is add an article to TechNet Wiki from your own specialist field. Something that fits into one of the categories listed on the submissions page. Copy in your own blog posts, a forum solution, a white paper, or just something
    you had to solve for your own day's work today.
    Drop us some nifty knowledge, or superb snippets, and become MICROSOFT TECHNOLOGY GURU OF THE MONTH!
    This is an official Microsoft TechNet recognition, where people such as yourselves can truly get noticed!
    HOW TO WIN
    1) Please copy over your Microsoft technical solutions and revelations to
    TechNet Wiki.
    2) Add a link to it on
    THIS WIKI COMPETITION PAGE (so we know you've contributed)
    3) Every month, we will highlight your contributions, and select a "Guru of the Month" in each technology.
    If you win, we will sing your praises in blogs and forums, similar to the
    weekly contributor awards. Once "on our radar" and making your mark, you will probably be
    interviewed for your greatness, and maybe eventually even invited into other inner TechNet/MSDN circles!
    Winning this award in your favoured technology will help us learn the active members in each community.
    Feel free to ask any questions below.
    More about TechNet Guru Awards
    Thanks in advance!
    Pete Laker
    #PEJL
    Got any nice code? If you invest time in coding an elegant, novel or impressive answer on MSDN forums, why not copy it over to
    TechNet Wiki, for future generations to benefit from! You'll never get archived again, and
    you could win weekly awards!
    Have you got what it takes o become this month's
    TechNet Technical Guru? Join a long list of well known community big hitters, show your knowledge and prowess in your favoured technologies!

    Happy New Year!
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

Maybe you are looking for

  • Ability to add multiple email addresses to the same contact person

    Hello SRM Experts, I have a question in SRM 5.0 In "Personal Data" tab of "Employee Data" in Manage Business Partner, we have the ability to add multiple email address. But only one email can be selected as standard. We have a new requiremnt that mor

  • How to deactivate my pandora account?

    II've been paying for my pandora account for years but I would like to erase the account and start over and I've emailed different people and it is not that simple. Can someone show me a short cut?

  • How can I view source on an app (preferably before installing)?

    An app for Firefox OS is programmed in HTML and JavaScript. So, just like a webpage, I should be able to View Source, right? That's always been the empowering Mozilla approach, as far as I understand. View Source is great for learning by example (jus

  • Setting the focus in HTREE

    Hi guys! I have created the tree in the form 6i. it is populated with the employee names. Then attached a horizontal toolbar canvas with the main form and the horizontal tool bar canvas contain a text item and a search button. When I find the name of

  • My external iPhoto folder is grayed out - how can I open it in iPhoto?

    My old Seagate external drive which had my iPhoto folder died but we were able to move a copy from my TimeMachine to my new LeCie external harddrive. But now when I try to open iPhoto and then point to the LeCia folder for my iPhoto Library - the fol