Yahoo! Pushing Java Version Released in 2008
Results 1 to 6 of 6

Thread: Yahoo! Pushing Java Version Released in 2008

  1. #1
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103

    Yahoo! Pushing Java Version Released in 2008

    From today's krebsonsecurity.com blog, here's a story that provides more evidence that large companies still aren't taking security seriously. Yahoo's Site Builder is using an ancient version of Java. As usual with most of Brian's blogs, the commentary is interesting and definitely a cut above the run of the mill.

    http://krebsonsecurity.com/2013/02/y...08/#more-18411

  2. #2
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    Of course they don't, look at the place I worked at, who couldn't take accountability for their lacking security blamed it on the guy who quit that knew more than all of them. Honestly this is exactly why I want to go free-lance again and focus on disaster recovery/triage of large companies who don't know how to handle infectors and believe that if the antivirus isn't detecting anything, then all is good.

  3. #3
    Registered User Ferrit's Avatar
    Join Date
    Apr 2001
    Location
    Vancouver Island The Real Canada
    Posts
    4,952
    Its dam sad thats for sure

  4. #4
    Registered User Niclo Iste's Avatar
    Join Date
    Oct 2007
    Location
    Pgh, PA
    Posts
    2,051
    Oh look another company who liked to pretend they didn't have issues..... http://krebsonsecurity.com/2013/02/e...ks/#more-18881

    You know, it's like having a conversation with someone about their seat belts being defective and them countering with a response of "I buckle up all the time and i haven't wrecked yet so they must work."

  5. #5
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    Particularly interesting stat from Sophos in the article: "80 percent of the Web sites where the company detects malicious content are innocent, legitimate sites that have been hacked." Nothing disturbing there.

    Still, the L.A Times response contains a real gem of stupidity: "The sub-domain generates only advertising content and does not contain any customer information." Right. It only facilitated infecting user computers with malware that could accomplish the same goal, so no worries, eh?
    Last edited by slgrieb; February 14th, 2013 at 12:19 PM. Reason: typo. again

  6. #6
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    Last edited by slgrieb; February 14th, 2013 at 12:25 PM.

Similar Threads

  1. Replies: 0
    Last Post: October 31st, 2012, 03:38 PM
  2. Mozilla browser version 1 released
    By Archer in forum Tech-To-Tech
    Replies: 2
    Last Post: June 7th, 2002, 04:23 PM
  3. Pushing my GF4 TI
    By Radical Dreamer in forum Gaming
    Replies: 1
    Last Post: March 25th, 2002, 07:36 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •