Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Java - JRE, SDK Java Web Start

Re: Java - JRE, SDK Java Web Start

From: Kish Pent <kish_pent_at_yahoo.com>
Date: Tue, 17 Jul 2007 10:57:36 -0700 (PDT)

Good question, first off :)

Hey Jfvanmeter,

> How does everyone feel about java being installed by
> vendors in a propriety path i.e. program
> files\mysoftware\bin\jre\1.4.0\ and never patching
> it.

> I ran an enterprise scan to looking for javaws.exe
> and found it in 175 unique paths. Should they be
> held accountable for the patching of java when they
> install it?

Indeed, the person who installs is accountable for it,
provided the SLA says so. ;)

Say if they provide support/after-sale support or
something along those lines, then they're supposed to
patch/install updates regularly.

> I had one vendor who installed java 1.3 and 1.4, and
> when I ask them about it. There statement was “you
> don’t have the modules that require those versions
> you can just delete them”

Tell them, that "This is the dumbest thing I've ever
heard" in all of my computing career. ;)

> How does everyone patch Java that is not installed
> in its default location?

AFAIK, it doesn't matter whether you install in your
root drive or not. All that matters is you patch it,
and the patch will be designed by Sun mostly to work
in almost all conditions, or else, this would be a big
deal to debate on, in their mailing list.

PS: How this patch thing works is, it retrieves your
settings/install settings from windows registry,
before it even starts to go further. Since you just
press update/or next->next->finish, you can't see this
going on in the background.

Cheers :)
Kish

Kishore
Penetration Tester
Smart Security
T.Nagar , Chennai
Phone: 91 98841 80767

 
____________________________________________________________________________________
Looking for earth-friendly autos?
Browse Top Cars by "Green Rating" at Yahoo! Autos' Green Center.
http://autos.yahoo.com/green_center/
Received on Jul 17 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos