Update: Oracle released an emergency patch recently to fix this major flaw. See details in the bottom.
————-
The recent discovery of a 0-day design flaw in the 'Java Web Start' module has opened new avenues for malware drive by attacks. This flaw was exposed by Tavis Ormandy a few days back and it did not take a long time for bad guys to start using the proof of concept code for real exploitation. I have been reading about the exploit details for the last few days, but very few details were available on the active use of this exploit. Who are the guys using this exploit and for spreading what? This article is all about this, with emphasis on the post infection stuff.
Users who are interested in the inner workings of this 0-day flaw itself, can read the full disclosure here.
It all started like this… yesterday afternoon my colleague Stuart Staniford pointed me to a malicious domain hxxp://zikkuat.com (dead at the moment) which he believed seemed to be exploiting this 0-day flaw. After a little analysis, I found it to be true indeed. Here are the details of my findings after a detailed analysis.







