Home » Mac, Reviews, how to, Security, Software

Java_Rhino: How to protect yourself

5 December 2011 3,690 views 3 Comments

There’s a nasty Java exploit making the rounds and it affects anyone with Java installed and enabled. However, protecting yourself is easy and will only take a couple minutes — update Java and then, unless, you use it all of the time, keep it disabled until you truly need it.

Metasploit’s Jonthan Cran describes the java-rhino exploit thusly, “This vulnerability is particularly pernicious, as it is cross-platform, unpatched on some systems, and is an easy-to-exploit client-side that does little to make the user aware they’re being exploited.”

My depth of understanding here is pretty minimal, but my impression is that this java_rhino is “script kiddy” easy to pull off. Happily, protecting yourself is just as easy.

Thereupon, get Apple’s Java updates for Lion or Snow Leopard and install the appropriate patch. Yes, just installing the latest version will block the java_rhino exploit.

Take the next step…

That said, I keep Java turned off in Safari and Firefox by default simply because it’s so infrequently needed and associated with so many stupid simple exploits. Although installing the latest version of Java from Apple obviates this particular attack vector, Java in general is so insecure that it always seems there’s another unpatched exploit circulating in the wild — I keep Java updated and turned off until it’s specifically needed.

To turn off Java in Safari, go to:

Preferences > Security > uncheck Enable Java (image above)

Lastly, JavaScript is just as buggy and prone to security issues, though JS is used everywhere and turning it off can cause performance and compatibility issues. Thereupon, you should consider running Drew Thaler’s JavaScript Blacklist (Safari extension) or a “noscript” extension.

What’s your take?

via News.com,

3 Comments »

  • Dan Knight said:

    And if we’re using OS X 10.4 Tiger or 10.5 Leopard, what can we do?

  • Lorne Pike said:

    Thanks for the warning. I thought I had the most recent Java update, but after reading this I checked it out and sure enough, I was out of date. Am back in form now; much appreciated!

  • OSX/Flashback.K: How to protect yourself | FairerPlatform said:

    [...] protect against Flashback.k, installing the most recent (November) update will protect you against Java_Rhino — Java updates for Lion and Snow [...]

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.