<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Real-time AntiSpam protection, automated and self-managed content filtering &#187; Netscape&#8217;s Java Virtual Machine</title>
	<atom:link href="http://veriat.com/tag/netscapes-java-virtual-machine/feed" rel="self" type="application/rss+xml" />
	<link>http://veriat.com</link>
	<description></description>
	<lastBuildDate>Thu, 27 May 2010 23:10:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Netscape Java Hole</title>
		<link>http://veriat.com/netscape-java-hole-2.html</link>
		<comments>http://veriat.com/netscape-java-hole-2.html#comments</comments>
		<pubDate>Tue, 18 Aug 2009 11:39:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Net Progress]]></category>
		<category><![CDATA[BugNet]]></category>
		<category><![CDATA[Netscape Java Hole]]></category>
		<category><![CDATA[Netscape Navigator]]></category>
		<category><![CDATA[Netscape's Java Virtual Machine]]></category>

		<guid isPermaLink="false">http://veriat.com/?p=326</guid>
		<description><![CDATA[It&#8217;s Netscape&#8217;s Turn for a Security Hole
Netscape Navigator users were able to chuckle as they read about the large number of security problems that have recently surfaced with Microsoft products. However, now it&#8217;s their turn to worry about a security hole.
BugNet has verified, using KeyLabs, reports of a potentially serious security hole for people who [...]]]></description>
			<content:encoded><![CDATA[<p><strong>It&#8217;s Netscape&#8217;s Turn for a Security Hole</strong></p>
<p>Netscape Navigator users were able to chuckle as they read about the large number of security problems that have recently surfaced with Microsoft products. However, now it&#8217;s their turn to worry about a security hole.</p>
<p>BugNet has verified, using KeyLabs, reports of a potentially serious security hole for people who use Netscape Navigator. The problem exists in Netscape&#8217;s Java Virtual Machine, which runs Java applets found on web pages, and was reported by security researcher Dan Brumleve. The exploit could be used to reverse normal browsing &#8211; files could be sent from your computer to the web site.</p>
<p><span id="more-326"></span></p>
<p>A web site operator could take advantage of this vulnerability to run code on a web surfer&#8217;s computer. This code would act as a file server, and could be used to offer up files from the surfer&#8217;s hard drive back to the web site. The code itself could be activated without the knowledge of the web browser. BugNet&#8217;s tests show that versions of Netscape running on Windows 95, Windows 98, and Windows 2000 are affected. The vulnerability can also be extended so that it can be used against people running Netscape on Macintosh and UNIX computers. BugNet has also gotten the exploit to work on Netscape for Linux, but only if the Linux user is surfing the web while logged in as &#8220;root&#8221;. Linux security gurus advise against that particular practice.</p>
<p>Normally, Java programs downloaded from the Internet run on your local computer in a &#8220;sandbox&#8221;. The program&#8217;s actions typically would not be allowed to extend beyond this sandbox, which makes the files on your hard drive off limits. Brumleve&#8217;s exploit manages to circumvent this restriction, which can give a hacker free reign on your system. Since many people have sensitive information stored in fairly standard locations on their hard drives (such as Quicken, TurboTax, or Microsoft Money files), the hacker could have many tempting targets. Even after you left the offending web page, the exploit would continue to run, staying active until Netscape Navigator is closed.</p>
<p>The Netscape Security Site, listed below, has not yet posted any fix. As a workaround, any Netscape user can disable Java on their machine. Do this by clicking Edit, Preferences. Click Advanced, and then uncheck Enable Java. Doing this may disable some features on web sites you visit, but will keep anyone from exploiting this particular security hole.</p>
]]></content:encoded>
			<wfw:commentRss>http://veriat.com/netscape-java-hole-2.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

