On 16/01/2013, at 11:17 AM, Bill Parker <[email protected]> wrote:
> Ronni, > > Another Bill here. Hi the real Bill, I thought I was originally replying to you; but it was Merv (I am supposed to be on a break from WAMUG so that is my excuse for using the incorrect name :-) > > Just looking at my Firefox Plugins and see Adobe Acrobat NPAPI 10.1.5 That plugin is for viewing PDFs in Firefox with Adobe Reader instead of the Preview application. > > and > > Java Applet 14.5.0 Mozilla has announced that they are also now blocking the Java plug-in unless the user specifically authorizes it to run by clicking on the warning message for the plug-in. <https://blog.mozilla.org/security/2013/01/11/protecting-users-against-java-vulnerability/> > > I have no other Java named plug-ins. Is Firefox the only web browser you have installed? If not check any other Web Browser. Cheers, Ronni > > Bill > On 15/01/2013, at 8:13 PM, Ronni Brown wrote: > >> Hi Bill, >> >> Java has not been safe for some time, we have recommended on WAMUG before >> that you disable Java in your Web Browsers. >> >> In Safari - Disable Java >> 1. Safari > Preferences, select Security >> 2. DON'T have a tick in "Enable Java" >> >> Disabling Java in Safari is highly recommended for safe computing. >> You should enable it only when on a trusted site that requires it. >> >> In Firefox: >> 1. Open Firefox and click the Firefox button -> Add-ons (Tools -> Add-ons in >> Linux, OS X and Windows XP). >> 2. Choose the Plugins tab. >> 3. Select the Java plugin(s) and click disable. >> >> "The U.S. Department of Homeland Security is urging computer users to >> disable or uninstall Java due to a serious flaw in Runtime Environment (JRE) >> 7. >> >> The DHS' Computer Emergency Readiness Team warned Thursday evening that it >> was being exploited in the wild and could allow an attacker to execute >> arbitrary code on vulnerable systems. >> >> CERT recommended that Java be disabled in Web browsers. It pointed users to >> theSolution section of the US-CERT Alert and to the Oracle Technical Note >> Setting the Security Level of the Java Client for information on how to do >> that." >> >> Cheers, >> Ronni >> >> On 15/01/2013, at 4:55 PM, Merv Bond <[email protected]> wrote: >> >>> My wife has been sent the following together with several links to other >>> pages. I didn't send the links in case they had the potential to do harm. >>> Can anyone make sense of this message? >>> Regards >>> Merv >>> >>> >>> Java exploit - serious consequences >>> >>> This has been the sequence of events when it has come to Java exploits >>> but this latest one is different, very different. Someone, deep inside a >>> bunker in China no doubt, has discovered that Java, at its core, is >>> insecure and it cannot be simply patched. The whole thing has been >>> compromised and needs to be rewritten. It would be like finding out that >>> the body of your car is made of blasting caps and if you hit anything >>> bigger than a moth it will explode. >>> -- The WA Macintosh User Group Mailing List -- Archives - <http://www.wamug.org.au/mailinglist/archives.shtml> Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.shtml> Settings & Unsubscribe - <http://lists.wamug.org.au/listinfo/wamug.org.au-wamug>

