← Back to team overview

openjdk team mailing list archive

[Bug 668314] Re: Trojan under Linux passing by Java ! ! !

 

from http://blogs.paretologic.com/malwarediaries/index.php/2010/10/27
/koobface-the-cross-platform-version/

  "If the user allows the applet to run ..."

so the user actively needs to confirm that he wants to run the applet.

-- 
Trojan under Linux passing by Java ! ! !
https://bugs.launchpad.net/bugs/668314
You received this bug notification because you are a member of OpenJDK,
which is subscribed to openjdk-6 in ubuntu.

Status in “openjdk-6” package in Ubuntu: Confirmed

Bug description:
Hi,

A trojan named "Boonana/Koobface" can be installed under linux because of java.
I thus confirm my request of real-time protection in ubuntu.

More information in French here:
http://www.echosdunet.net/dossiers/dossier_6179_un+trojan+windows+passe+sous+mac+os+x+linux+via+java.html

Why not make a real-time protection to clamav inspired by "sentinel clam" ?

ProblemType: Bug
DistroRelease: Ubuntu 10.10
Package: icedtea6-plugin 6b20-1.9.1-1ubuntu3
ProcVersionSignature: Ubuntu 2.6.35-23.36-generic 2.6.35.7
Uname: Linux 2.6.35-23-generic x86_64
NonfreeKernelModules: nvidia
Architecture: amd64
Date: Fri Oct 29 14:29:14 2010
InstallationMedia: Ubuntu 10.10 "Maverick Meerkat" - Release amd64 (20101007)
ProcEnviron:
 LANG=fr_FR.utf8
 SHELL=/bin/bash
SourcePackage: openjdk-6