Dot Matrix Posted January 16, 2013 Share Posted January 16, 2013 One day after patching a massive zero day exploit, Oracle once again finds themselves in a hole with a new zero day exploit found in Java. On Monday, a hacker posted a message he was selling a new zero day kit to lucky buyers - for $5,000 each. ?New Java 0day, selling to 2 people, 5k$ per person And you thought Java had epically failed when the last 0day came out. I lol?d. The best part is even-though java has failed once again and let users get compromised? guess what? I think you know what I?m going to say? there is yet another vulnerability in the latest version of java 7. I will not go into any details except with seriously interested buyers. Code will be sold twice (it has been sold once already). It is not present in any known exploit pack including that very private version of [blackhole] going for 10$k/month. I will accepting counter bids if you wish to outbid the competition. What you get? Unencrypted source files to the exploit (so you can have recrypted as necessary, I would warn you to be cautious who you allow to encrypt? they might try to steal a copy) Encrypted, weaponized version, simply modify the url in the php page that calls up the jar to your own executable url and you are set. You may pm me. Oh, dear... Link to comment https://www.neowin.net/forum/topic/1131200-yet-another-java-zero-day/ Share on other sites More sharing options...
Brandon H Supervisor Posted January 16, 2013 Supervisor Share Posted January 16, 2013 somehow not surprised oracle needs to sit down a bunch of white collar hackers and have them crunch away for awhile Link to comment https://www.neowin.net/forum/topic/1131200-yet-another-java-zero-day/#findComment-595458088 Share on other sites More sharing options...
Growled Member Posted January 17, 2013 Member Share Posted January 17, 2013 Java is a disaster waiting to happen. Nothing Here 1 Share Link to comment https://www.neowin.net/forum/topic/1131200-yet-another-java-zero-day/#findComment-595459270 Share on other sites More sharing options...
siah1214 Posted January 17, 2013 Share Posted January 17, 2013 Java is a disaster. Fixed that for ya ;) Growled 1 Share Link to comment https://www.neowin.net/forum/topic/1131200-yet-another-java-zero-day/#findComment-595459276 Share on other sites More sharing options...
Lord Method Man Posted January 17, 2013 Share Posted January 17, 2013 Ah Java... Link to comment https://www.neowin.net/forum/topic/1131200-yet-another-java-zero-day/#findComment-595459278 Share on other sites More sharing options...
123456789A Posted January 17, 2013 Share Posted January 17, 2013 Java is a disaster waiting to happen. The disaster has been happening for a while already. Link to comment https://www.neowin.net/forum/topic/1131200-yet-another-java-zero-day/#findComment-595459290 Share on other sites More sharing options...
Recommended Posts