New Java Zero-Day Exploit Shows Multi-Platform Development - The Mac Security Blog
Java zero day vulnerability actively used in targeted attacks | ZDNet
Java zero day allegedly spotted in the wild | ZDNet
Question to get the discussion going on how this UTM can protect us against this attack.
1) How do you know if your Astaro IPS would be protecting you against this?
2) Avira AV?
3) SOPHOS AV?
4) SOPHOS End Point Security and Control.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
XG 19.5 GA 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
16GB Memory | 500GB SSD HDD | GB Ethernet x5
From my understanding, the Sophos updates are a 'live update' meaning that Sophos has 24/7 updating going on with the signatures for their AV products, which include the Astaro features and Endpoint Protection clients. So, as soon as they identify it and can apply a signature for it, it will be distributed and you may actually see the version, date, etc. posted.
For now, I will just tell Astaro to block all Java. [:)]
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
The HTTP/S Proxy has an option to remove Java Content in the configuration section.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
I seriously do not like the idea that it is so hard for me to know for sure that the UTM is capable of blocking this.
Look at Symantec and Trend Micro, they would describe below the Threat how their various products would defend this, any recommended settings, what to look out for for signs of successful attacks etc.
INCOMING ATTACK !
Malware Intelligence Lab from FireEye - Research & Analysis of Zero-Day & Advanced Targeted Threats:Java Zero-Day - First Outbreak
Hey Guys - I am adding thet list of domains to be blocked at the Packet Filter to block ANY TO and ANY FROM the Malicious Domain = DROP.
Any other settings ?
No Idea if SOPHOS Content Filtering added it.
Zero-day Java flaw exploited in targeted tax email malware attack | Naked Security
Java Runtime Environment 1.7 Zero-Day Exploit Delivers Backdoor | Malware Blog | Trend Micro
OSX/Tsunami Variant Found Dropped by Java 0-Day - The Mac Security Blog
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
The exploit is being blocked by both Avira and Sophos (for those on v9) AV engines as long as your patterns are up to date.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow