Java! Uninstall It, Update it, or bend over and grab the ketchup!


Recommended Posts

Java! Uninstall It, Update it, or bend over and grab the ketchup!

For some of you, this is news!

If you have it, but don't know you explicitly really need it, please uninstall it immediately!!

Java is bad. Not by itself, but by the exploits it brings along with it. While you may have the most current version, the bad guys always seem to keep a zero day vulnerability close to their hearts!

The current version of Java (version 7) does in fact use DEP. Which should (in theory keep Vista and Windows 7 users safe, until proven it doesn't). For those of you using XP, you should come up with a really good reason why you still need java.

My mom who does stock trading. I tell her, "Please keep java updated. Only use Java with IE. The rest of the time, use Java Firefox and the Quickjava extension with Java DISABLED!"

While a lot of you love java, (I Love a cup of coffee as much as the next guy) Please take Java seriously, otherwise you may be looking down a malware infested barrel, called a rootkit infested machine!

For those of you who know and program in Java and are OK with the consequences of having it installed "More power to you!".

For the rest of the Neowin members, if you have Java, that's great, but please (for the love of god) keep it up to date, or disabled until you need it!

Walfgang Kandek, CEO of Qualys, said that the 200,000 who visited broswere security service BrowserCheck in July 2010 ? January 2011, 42% of them were running versions of plug-in Java that had not been updated and contains known vulnerabilities. Only 24% of them were older versions of Flash that include also vulnerabilities. Other applications risky because old versions are Adobe Reader (32%) and Apple QuickTime(25%).

During 2010, Oracle released several updates to address vulnerabilities Java . One last update addresses a group of 21 vulnerabilities, 8 of them considered critical. 19 of which can be exploited through a network not valid without the required login data. It is the second warning that draws attention to Java , after the December, released by Cisco, which announced that attacks through Java had surpassed the number on the Adobe Reader and Acrobat in 2010.

From that blog post:

?During the one year period starting in the third quarter of 2010 (3Q10) and ending in the second quarter of 2011 (2Q11), between one-third and one-half of all exploits observed in each quarter were Java exploits[1]. During this one year period, Microsoft antimalware technologies detected or blocked, on average, 6.9 million exploit attempts on Java related components per quarter, totaling almost 27.5 million exploit attempts during the year.?

The exploit attacks a vulnerability that exists in
Oracle Java SE JDK and JRE 7 and 6 Update 27
and earlier. If you are using
Java 6 Update 29
, or
Java 7 Update 1
, then you have
that is patched against this and 19 other security threats. If you are using a vulnerable version of Java, it?s time to update. Not sure whether you have Java or what version you may be running? Check out
, and then click the ?Do I have Java?? link below the big red ?Free Java Download? button. Apple
to fix this flaw and other Java bugs earlier this month.

What's so special about Java that it deserves its own thread? Doesn't this rule apply to any software; update it or risk getting infected.

This plus just disable Java in your browser. That's what I do since only thing I use Java for is Minecraft.

I work in information security where we have IDS's setup. We regularly see java getting owned and malware being installed even on current versions within corporate environments. On peoples home PC's..yikes...

I fricking hate Java.. I think the fundamental concepts of the language, and it being cross platform etc are excellent but like so many things to do with Oracle, it's just been horrendously implemented.

It seems to need updating on a near weekly basis and even if you turn off automatic updating, it still bugs you about updating. Not to mention how unreliable it is and the penchant it has for locking up / breaking. Hateful. I just wish it would go away and die somewhere quietly, and take Oracle with it.

Will NEVER install Suns version of this total POS software!!

The ONLY use I have really ever seen for this bloated, insecure junk is java speed tests. I simply don't run those.

The 3 most attacked (and crappiest) pieces of software ever written, IMO, are java, flash, Windows!!

I would remove it, but i can't I am a java programmer and I need it to make server applications with!! :p I would NEVER EVER use Java for desktop applications period, but for server applications its great :)

People are always asking me how to stay secure with their computers. Then I spin into the "keep Windows up to date, keep adobe up to date, adobe everything, and keep java up to date.

After their eyes stop glazing over I then walk over to the "laptop", remove java from the control panel, stop the computer from going to sleep every 20 minutes, and set Windows updates to happen at 3pm every day not 3am. Then I update Adobe and hope that they get the Adobe download that asks if you want to keep it up to date automatically. Where can I make that happen anyway? I can't seem to find that download all the time. Sometimes Adobe will provide a check mark to keep it updated automatically and sometimes it won't.

Then I put on MSE because it pretty much takes care of itself and set it to also scan once a week during the day. THEN I tell them to try and leave the computer on at 3pm every now and then to insure all the updates happen. OR do the updates manually.

Is it too much to ask the consumer to keep their computers updated to avoid getting viruses? That's the easiest question of all. YES. Warwagon knows...

I removed Java 7 and 6. I like playing dominoes and yahoo pool.

They don't work on it.

J2SE v1.5.0 is what yahoo tries to install and that works.

I wish we could have ms virtual machine which I enjoyed, but, NO.

I would remove it, but i can't I am a java programmer and I need it to make server applications with!! :p I would NEVER EVER use Java for desktop applications period, but for server applications its great :)

Wait, what? People are actually using JAVA applications on servers? Is it a heavy-load server or just a server that runs JAVA applications for some small tasks?

Wait, what? People are actually using JAVA applications on servers? Is it a heavy-load server or just a server that runs JAVA applications for some small tasks?

http://en.wikipedia.org/wiki/Java_Platform,_Enterprise_Edition

Java should be destroyed entirely. The only reason that it exists is that the .NET framework hasnt been opened to other OSs. If so, C# would **** all over it.

Uh, check out Mono. Woops, there goes your theory.

Java exists for a few very good reason, though you may not be aware of them.

Is it too much to ask the consumer to keep their computers updated to avoid getting viruses? That's the easiest question of all. YES. Warwagon knows...

I think ANYBODY who's worked in the repair industry knows - it's impossible :p

Wait, what? People are actually using JAVA applications on servers? Is it a heavy-load server or just a server that runs JAVA applications for some small tasks?

There are servers that actually run on Java, yes. Depending on the situation, it can make a lot of sense.

http://en.wikipedia....avaServer_Pages

http://en.wikipedia.org/wiki/Sun_Java_System_Web_Server

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Everyone should install this extension and ignore games that use AI. https://chromewebstore.google....nnigaaeelfkeomjcngmnh?pli=1
    • Malwarebytes Anti-Malware 5.6.0.256 by Razvan Serea Malwarebytes is a high performance anti-malware application that thoroughly removes even the most advanced malware and spyware. Malwarebytes version 5.**** brings comprehensive protection against today’s threat landscape so that you can finally replace your traditional antivirus. You can finally replace your traditional antivirus, thanks to a innovative and layered approach to prevent malware infections using a healthy combination of proactive and signature-less technologies. While signatures are still effective against threats like potentially unwanted programs, the majority of malware detection events already come from signature-less technologies like Malwarebytes Anti-Exploit and Malwarebytes Anti-Ransomware; that trend will only continue to grow. For many of you, this is something you already know, since over 50% of the users already run Malwarebytes as their sole security software, without any third-party antivirus. What's new in Malwarebytes 5.****: Unified user experience - For the first time, Malwarebytes now provides a consistent experience across all of our desktop and mobile products courtesy of an all new and reimagined user experience powered by a faster and more responsive UI all managed through an intuitive dashboard. Modern security and privacy integrations - Antivirus and ultra-fast VPN come together seamlessly in one easy-to-use solution. Whether you’re looking for a next-gen VPN to secure your online activity, or harnessing the power of Browser Guard to block ad trackers and scam sites, taking charge of your privacy is simple. Trusted Advisor - Empowers you with real-time insights, easy-to-read protection score and expert guidance that puts you in control over your security and privacy. Malwarebytes 5.6.0.256 changelog: Features and improvements Simplified adding files and folders to the Allow list to make managing your exclusions easier. Improved notifications for Webcam Monitoring. Issues fixed Resolved an issue preventing the Deep Scan results window from displaying when several threats are detected during a scan. Fixed text wrapping issues on the Settings page. Fixed an issue causing tray menu notifications to appear off-screen when using multiple external monitors. Download: Malwarebytes 5.6.0.256 | 436.0 MB (Free, paid upgrade available) Links: Malwarebytes Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Steam Next Fest returns with thousands of new demos to try out by Pulasthi Ariyasinghe Valve has been routinely kicking off demo festivals on Steam for years now, and the second drop of 2026 has just opened its doors. It's a great opportunity for any PC gamers to find some interesting games before they release. The June edition of Steam Next Fest is a week-long digital festival including gameplay slices from a large number of indie developers, though a few major publishers are involved this time too. Interested players can use the Next Fest hub page's various sorting and filtering options to easily sort through the hordes of demos available. The top buttons offer quick access to separate and important sorting options, including "By Genre, By Theme, By Feature," with each one offering more granular settings when clicked. At the same time, the built-in Steam tags system is also available below every page to discover new games more quickly. As always, logging in will also enable Steam gamers to utilize Valve's recommendation algorithms to find game demos they might like, specifically, depending on their past play and purchase histories. This time there is even a toggle now to swap between getting a random and personalized selection as Valve collects more data on the available demos. The Charts section is where you can find the most popular demos on the platform right now, offering up the most hyped titles in a simple list. Right at the kickoff, Mistfall Hunter, Empulse, Echoes of Aincrad, Onimusha: Way of the Sword, Over the Hill, Mortal Shell II, and more are trending. Expect this list to change as the week progresses. This edition of the Steam Next Fest is slated to end on June 22 at 10 AM PT. Valve's latest event is now open, and it can be accessed by going to the dedicated hub page here.
    • I lived and breathed MSN Messenger/Windows Live Messenger. Going to the mess.be website (still online with no changes since 2013) to download display pictures etc. I was a beta tester for Messenger Plus! and spent quite a lot of time on the MsgPlus! forums (a read-only copy is still online at https://shoutbox.menthix.net) Some old Neowin articles also https://www.neowin.net/news/messenger-plus-350/ good times but how time flies The main developer of Messenger Plus!, Cyril aka. Patchou has released a game https://store.steampowered.com/app/3275440/Pluralys/
  • Recent Achievements

    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      82
    5. 5
      ATLien_0
      76
  • Tell a friend

    Love Neowin? Tell a friend!