Sometimes I briefly wonder what the world would be like if everyone just removed the Java web plugin. Would hackers be forced to move to Flash? But Flash is sandboxed for all major browsers. Social engineering? I guess.

But no, the truth of the matter is if you can’t take the 5 seconds to exploit Java you can just take a few days to exploit something else.

Vupen and Metasploit and others always show this to be the case – nothing is beyond exploitation.

Inspired by Exploitation Of Internet Explorer MSXML Remote Uninitialized Memory.



blog comments powered by Disqus

Published

18 July 2012

Categories