UNSOLVED

PeterSwiss

updated

21 years ago

P

PeterSwiss

99 Posts

0

10805

February 17th, 2006 19:00

Dell Delivers vulnerable java (SE v1.4.2_03.msi), currently exploited.

I received my Inspiron on Aug 23, 2005, with Java SE v1.4.2_03 installed. That Java version is, and was, a known vulnerable version. A more save version, jre-1_5_0_06 has been available since long (older versions, e.g. 1_5_0_02 seem vulnerable too). It is important to uninstall the old version first, and then install the new version.
 
Recently there are again sites that exploit vulnerability of this version (1.4.2). Symptoms of the infection are presence of a anima.class, a omfg.class, that are the exploit. The payload can be zdj.exe, intell321.exe, hpwarn.html, lich.exe, oleext.dll, oleext32.dll and ( edit-add) wininet.dll .This payload collects information into a random file x......tmp in the C:\Windows directory. The payload is known only to Sophos. The method is documented at http://www.mullingsecurity.com/2006/01/old-java-bug-exploited-from-ukraine.html
 
The standard Spyware and virus tools did, as of yesterday, not prevent anything or detect it. It was necessary to reinstall Windows from the Windows setup CD. After that I identified and removed the files by their creation date, and of course disabled their automatic start.
 
(edit-add) As of one day later, updated AVG found the infecting files.

Message Edited by PeterSwiss on 02-19-2006 12:45 PM