A security loophole in the Java
Deployment toolkit endangers
the computer, enables externally
execution of commands and bypasses
the security measures of Vista and
Windows 7. Can this risk be removed?
The Java Web Start Launcher in the toolkit can be externally controlled with the desired parameters. This tool is automatically positioned on the computer along with the installation of certain versions of the Java Runtime Environment. While Firefox automatically disables the plug-in, you need to take care of this danger on the Internet manually. Disabling the plug-in is not enough.
Enter ‘regedit’ in the input fi eld of ‘Start | Run’ and press Enter. Confirm the next query about the user control panel with ‘Continue’. In the Registry Editor, navigate to the key ‘KHEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility’. Search for the Class ID ‘{CAFEEFAC-DEC7- OOOO-OOOO-ABCDEFFEDCBA}’ as the sub-key. On the right side of the dialog window, double-click the DWORD value ‘Compatibility Flags’. Then confirm the setting with ‘OK’ and close the registry. The set ‘Kill Bit’ can then no longer call up the relevant ActiveX control element in Internet Explorer.
The Java Web Start Launcher in the toolkit can be externally controlled with the desired parameters. This tool is automatically positioned on the computer along with the installation of certain versions of the Java Runtime Environment. While Firefox automatically disables the plug-in, you need to take care of this danger on the Internet manually. Disabling the plug-in is not enough.
Enter ‘regedit’ in the input fi eld of ‘Start | Run’ and press Enter. Confirm the next query about the user control panel with ‘Continue’. In the Registry Editor, navigate to the key ‘KHEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility’. Search for the Class ID ‘{CAFEEFAC-DEC7- OOOO-OOOO-ABCDEFFEDCBA}’ as the sub-key. On the right side of the dialog window, double-click the DWORD value ‘Compatibility Flags’. Then confirm the setting with ‘OK’ and close the registry. The set ‘Kill Bit’ can then no longer call up the relevant ActiveX control element in Internet Explorer.
0 comments:
Post a Comment
please write your comment
Note: Only a member of this blog may post a comment.