Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

Do you need to uninstall Java to be safe from its vulnerabilities?-gctid70493

Started by Ajamu, Jan 18, 2013, 05:35 PM

Previous topic - Next topic
Do you need to uninstall Java to be safe from its vulnerabilities? | Security & Privacy - CNET News



'"').'")."n[/list]"'

With  the latest security holes coming to light, many are recommending  removing Java entirely from your system. If you don't want to go that  far, here are some things you can do.
     by Topher Kessler
    January 16, 2013 6:19 PM PST  
   
   

 Lately Java has been getting a bit of bad press, thanks to several consecutive security holes that have been exploited by malware developers. One notable occurrence was the Flashback malware  threat that affected a number of OS X users, which (though due in part  to Apple's negligence about Java upkeep) was rooted in the Java runtime.  More recently, Java 7 has seen a new zero-day vulnerability that has  been circulating in exploit kits.

 In response to these threats, many in the tech community have  recommended that people uninstall Java altogether. However, this can be  impractical for some, as many people need Java to run applications,  including Web apps and a number of technical and creative development  tools.

  Related stories

'""'
 
 When it comes to the security of your system, uninstalling Java  completely is certainly one way to avoid problems arising from it, but  it is a bit of an extreme measure. So, how do you secure your system  while keeping a potentially faulty runtime installed?

 There are two aspects to Oracle's Java installation. The first is the  runtime itself, which consists of the libraries and execution  environment that allow your system to execute Java programs. The second  component of the installation is the Web plug-in, which interfaces these  libraries with the browser to allow hosted Web applets to run.

 

In older versions of Java (1.6 or earlier)  Safari's security preferences could be used to disable Java, but this is  now done in the Java Control Panel in the system preferences.
  (Credit: Screenshot by Topher Kessler/CNET)  

 The vast majority of Java's security problems revolve around the use  of the Java plug-in. While the vulnerabilities ultimately exist in the  runtime, the plug-in is the avenue that malware developers use to  exploit these remotely. You are somehow tricked into loading a Web page  that contains a malicious Java applet, which exploits the fault and  loads malware on to your system. If you close this off or otherwise  manage it, then you will vastly improve the security of your system, and  can continue to use Java for other purposes without needing to remove  it completely.

 There are several ways to do this. In the latest Java runtime, you  can access the Java Control Panel and in the security settings uncheck  the option to "Enable Java content in the browser." This will  effectively close the door between Java and Web sites you visit, so Java  applets will not run. While technically the security vulnerabilities  are still open with this setting, you would need to manually download a  Java executable and purposely run it on your system.

 

When ClickToPlugin is enabled, your plug-in content is shown like this, and only is active if you explicitly click it.
  (Credit: Screenshot by Topher Kessler/CNET)

The second option is the use of security levels in determining which  Java code is allowed to run. Similar to Apple's Gatekeeper feature in  Mountain Lion, which can restrict running applications to signed code or  apps specifically from the Mac  App Store, Java's security levels can require that you approve any  unsigned applications or even approve all code regardless of its  signature. To do this, in the same Security section of the Java control  panel, you can drag the security level slider to High, which allows only  signed programs to run, or Very High, which requires approval for all  code.

 Beyond Java's built-in security measures, you can also use some  third-party tools to help prevent malicious Java applets from running on  your system. While disabling the Java plug-in is perhaps best, if you  regularly visit Web sites that require Java, then doing this can be a  burden to your work flow. Therefore, instead use a plug-in manager such as ClickToPlugin  that will block not only Java but also Flash and other plug-in content  as well. The benefit here is instead runnng of the blocked content,  you'll receive a notification that you can click to quickly allow it to  run. Also, you can customize a whitelist of sites that are automatically  allowed to work.

 Some browsers like Chrome come with a click-to-play option, which can  be seen by going to Chrome's content settings (Copy and paste this URL  into Chrome to get to these settings:  chrome://chrome/settings/content#click) and selecting the "Click to  play" option in the Plug-ins section. For those who use Firefox, the NoScript plug-in is a very effective approach to managing unwanted execution of plug-ins and other Web-based content.

 A final approach to help protect your system is to monitor outgoing traffic using a reverse firewall tool like Little Snitch.  With such a tool installed, whenever a program tries to contact an  external server, the system will notify you and give you options to  allow or deny the attempt, and also provide you with information to  investigate what process is making the request.

 

When Little Snitch detects an outgoing  connection, it will notify you and provide information on what the  process is and who it is attempting to contact.
  (Credit: Objective Development)  

 While this is a bit of a tangential approach to dealing with faults  in Java, it has been a very useful and effective way to detect malicious  behavior on systems in the past and was integral to the early detection of the Flashback malware in OS X.  While such firewalls may not prevent malware from exploiting your  system, they can prevent it from carrying out its primary purpose, which  is to communicate personal information to an external server and open  up unwanted command and control ports in the system.

 Overall, while Java has seen its fair share of problems and exploits  recently, and although the most secure route is to uninstall Java and  avoid using it, this is not necessary to keep your system secure. With  plug-in management, higher security settings for Java, and reverse  firewalls to detect malicious activity, you can still keep Java  installed for the purposes you need while giving yourself an advantage  in fighting the tricks that malware uses to cause problems in your  system.


How to disable Java in IE, Firefox, Chrome, and Safari | How To - CNET

 The  unpatched Java vulnerability reported last week could be exploited by  malware to infect your system, although no such infections have been  discovered to date.

   by Dennis O'Reilly

    October 1, 2012 4:28 PM PDT

Last week's notice by researchers at Security Explorations  of an unpatched hole in the Java runtime environment may have left you  wondering whether to disable Java until Oracle releases a patch. CNET's  Topher Kessler noted in his report on the Java flaw that no malware exploiting the vulnerability has yet been documented.

Which leads to the question, "Do I need Java?"

The best way to find out is to disable Java in your browser and  re-enable it only if you encounter a site that prompts you to download  Java before it will open. Then you can activate the Java plug-in by  following the steps below in reverse, and perhaps disable the plug-in  again after you leave the site.

(While researching this topic I discovered that one of my test PCs  has been browsing flawlessly for more than a year without the Java  runtime environment installed.)

These steps will disable Java in Internet Explorer 9, Firefox 15.0.1, Google Chrome 22, and Safari  6.0.1. If you're using an older version of these browsers, update to  the latest release. (More information on software updaters is found at  the end of this post.)

Disable Java in IE 9 via the 'Manage add-ons' option

 Click  IE 9's gear icon in the top-right corner of the window and choose  "Manage add-ons." Select Toolbars and Extensions in the left pane under  Add-on Types and scroll to the entry for the Java plug-in under "Sun  Microsystems Inc." Choose the Java entry and click Disable in the  bottom-right corner.

Disable Java in Internet Explorer 9 by opening Manage Add-ons, selecting the Java entry, and clicking Disable.
  (Credit: Screenshot by Dennis O'Reilly/CNET)  

The next time you start IE, a notice will appear at the bottom of the  window informing you that the Java plug-in is ready to use. Click the  "Don't enable" button or the x on the right of the pop-up to continue  browsing Java-free.

After you disable Java in IE you'll be prompted to enable the plug-in the next time you open the browser.
  (Credit: Screenshot by Dennis O'Reilly/CNET)

Firefox's Java plug-in can be disabled in a jiffy

 To  prevent the Java plug-in from running in Firefox, click Tools >  Add-ons to open the browser's add-on manager. (If you don't see the menu  at the top of the Firefox window, press the Alt key.) Choose Plugins in  the left pane, scroll to the entry for the Java plug-in, and click its  Disable button.

Disable Firefox's Java plug-in via the browser's Add-on Manager.
  (Credit: Screenshot by Dennis O'Reilly/CNET)

(When I checked this Firefox setting on one of the PCs in my home  office the Java SE 6 plug-in had been disabled automatically because  Firefox identified it as vulnerable. Updating to Java SE 7 re-enabled  the plug-in in Firefox automatically.)

Turn off Java in Google Chrome

 You can disable Java in  Chrome by entering "chrome://plugins" in the address bar and pressing  Enter to display a list of the browser's plug-ins. Scroll to the entry  for Java and click Disable.

Click Disable under the entry for Java in Google Chrome's list of plug-ins to prevent the add-on from running automatically.
  (Credit: Screenshot by Dennis O'Reilly/CNET)

Put Java on the shelf in Safari

 To shut down Java in  Safari, click Safari > Preferences (or press Command-,), select the  Security tab at the top of the window, and uncheck Enable Java.

Open Safari's Preferences window and choose the Security tab to disable Java in Apple's browser.
  (Credit: Screenshot by Dennis O'Reilly/CNET)

A word about drive-by downloads

 Every time I write about  Java or Adobe's Flash Player, I begin my making sure I have the most  recent versions of the plug-ins. And every time I update the two  programs manually I'm prompted to download a free security scanner:  McAfee Security Scanner for Java and Norton Security Scan for Flash.

It's bad enough that the scans aren't directly related to Java or  Flash, but in both instances the option to scan your system is selected  by default. People in a hurry will click OK to install the update  without realizing they're getting more software than they expect. Unless  you want to prolong the update process by adding a malware scan you may  not need, be sure to uncheck the scan options whenever you update  either plug-in.

Also, the confusion between Java and JavaScript continues unabated.  The two technologies are unrelated despite their similar names. While  JavaScript poses its own potential security problems, the scripting  language is not affected by Java vulnerabilities.

If your browsers and other programs are updated with the latest  versions, there's probably no need to disable JavaScript. For more on  keeping your software up-to-date, read my review of three free patch-management utilities from May 2011.

@Ajamu..yup that's what I was talking about, you proved the finite details.

How to Protect Yourself From Java Security Problems if You Can't Uninstall It


 
For years, Java has been the top source of browser exploits. Even  after a recent emergency patch, Java is still vulnerable. To protect  ourselves, we should assume that Java is always going to be vulnerable.

We've already recommended disabling Java completely.  Most people with Java installed don't need it – it's just sitting on  their computers waiting to be exploited. You should uninstall Java now,  if you can.

However, some people still need Java installed, whether for playing  Minecraft or using an old Java applet on their company's intranet. If  you're one of them, these tips will help you stay as safe as possible.

 Remove Java Entirely If You Can!

 If you don't use Java for anything, you should uninstall it right  now. if it's installed, you'll find it in the list of installed programs  in your Control Panel. If you're not sure whether you need Java, try  uninstalling it anyway. You probably won't even notice that it's gone.

If you can't uninstall Java yet and still need it, we'll give you  some strategies for mitigating the security problems you face with Java  installed.


 If You Only Use Java Desktop Programs

 If you need Java installed, there's a good chance you only use it for  desktop programs like Minecraft or the Android SDK. If you only need  Java installed for desktop applications, you should ensure Java browser  integration is disabled. This will prevent malicious websites from  loading the Java browser plugin to silently install malware using one of  the many Java vulnerabilities that regularly becomes exploited online.

First, open the Java Control Panel by pressing the Windows key,  typing Java, and pressing Enter. (On Windows 8, you'll need to select  the Settings category after typing Java).

Click the Security tab and uncheck the Enable Java content in the browser checkbox.  This will disable the Java plug-in in all browsers on your computer,  although downloaded applications will still be able to use Java.


 
This option is fairly new and was introduced in Java 7 Update 10.  Previously, there was no easy way to disable Java in all browsers on  your computer.

 If You Use Java in Your Browser

 If you're one of the minority of people who needs to use Java applets  in your browser, there are some steps you can take to lock things down.

You should have multiple browsers installed –  your main browser with  Java disabled and a secondary browser with Java enabled. Use the  secondary browser exclusively for websites where you need Java. This  will prevent websites from exploiting Java during your normal browsing.

Follow the steps here  to disable Java in your primary browser. Use the secondary browser only  to run Java applets on trusted websites, such as your company's  intranet. If you don't trust a website, don't run Java content from it.


 
You may also want to enable click-to-play plugins in Chrome or Firefox. This will prevent Java (and Flash) content from running until you allow it.


 

Keep Java Updated!


 If you do keep Java installed, ensure you keep it updated. To change  your Java update settings, open the Java Control Panel from earlier and  use the Update tab.

Ensure Java is set to check for updates automatically. (You can also run a manual update by clicking Update Now.)


 
You should also click the Advanced button and set Java to check for  updates once per day. By default, it checks once a month or week – way  too infrequently for such as vulnerable piece of software. Whenever you  see a Java update balloon appear in your system tray, update Java soon  as possible.


 
Older Java versions left the old, vulnerable versions installed when  they updated. Luckily, newer versions of Java clean up older versions  properly. However, even the latest security patches won't protect you  from everything. The latest version of Java is still vulnerable, even  after an emergency patch.

 
Note that Java isn't the same as JavaScript – JavaScript is a  completely different language built into web browsers. It's a bit  confusing, but we can blame Netscape and Sun for that.