<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; jar</title>
	<atom:link href="http://www.ghacks.net/tag/jar/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Attack: Combine Files With Jar Scripts</title>
		<link>http://www.ghacks.net/2008/08/01/new-attack-combine-files-with-jar-scripts/</link>
		<comments>http://www.ghacks.net/2008/08/01/new-attack-combine-files-with-jar-scripts/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 16:22:34 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[gifar]]></category>
		<category><![CDATA[jar]]></category>
		<category><![CDATA[jar gif]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java applets]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=5782</guid>
		<description><![CDATA[A new attack, dubbed Gifar by their creators named after the two file types that they mixed to create the attack (Gif and Jar), was mentioned in a Black Hat Sneak Preview article over at ZDnet. While not everything was revealed in that preview article it mentioned that the developers were able to combine two [...]]]></description>
			<content:encoded><![CDATA[<p>A new attack, dubbed Gifar by their creators named after the two file types that they mixed to create the attack (Gif and Jar), was mentioned in a Black Hat Sneak Preview article over at <a href="http://blogs.zdnet.com/security/?p=1619">ZDnet</a>. While not everything was revealed in that preview article it mentioned that the developers were able to combine two file types like the previously mentioned gif and jar files so that the first, container file type, would be shown normally in the browser but that the Java applet would be executed at the same time.</p>
<p>Many file and image hosts filter dangerous file types. If you tried to upload a Jar file to most of them you would get an error message stating that the file type was not supported. Many however fail to analyze the file itself and simply reject files based on their extension which opens the door for this attack.</p>
<p>That&#8217;s a pretty dangerous exploit. Imagine someone who uses this to upload a new avatar to popular websites like <a href="http://www.ghacks.net/2009/10/17/facebook-login/">Facebook</a> or Myspace (two examples, I have not checked if the two use advanced upload filters). He could do all sorts of things with the Java Applet once users open up his profile page.</p>
<p><span id="more-5782"></span>The only valid defense against this type of attack is to disable Java on the computer for the moment. Sun is already working on a fix although the researchers say that it is not Sun&#8217;s fault that this vulnerability exists.</p>

	Tags: <a href="http://www.ghacks.net/tag/browser/" title="browser" rel="tag">browser</a>, <a href="http://www.ghacks.net/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a href="http://www.ghacks.net/tag/gifar/" title="gifar" rel="tag">gifar</a>, <a href="http://www.ghacks.net/tag/jar/" title="jar" rel="tag">jar</a>, <a href="http://www.ghacks.net/tag/jar-gif/" title="jar gif" rel="tag">jar gif</a>, <a href="http://www.ghacks.net/tag/java/" title="java" rel="tag">java</a>, <a href="http://www.ghacks.net/tag/java-applets/" title="java applets" rel="tag">java applets</a>, <a href="http://www.ghacks.net/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2007/03/31/send-windows-to-nirvana-with-an-animated-cursor/" title="Send Windows to Nirvana with an animated cursor (March 31, 2007)">Send Windows to Nirvana with an animated cursor</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/06/27/you-better-stop-using-internet-explorer-for-now/" title="You better stop using Internet Explorer for now (June 27, 2008)">You better stop using Internet Explorer for now</a> (18)</li>
	<li><a href="http://www.ghacks.net/2009/03/06/windows-xp-default-internet-browser-per-user-profile/" title="Windows XP: Default Internet Browser Per User Profile (March 6, 2009)">Windows XP: Default Internet Browser Per User Profile</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/06/13/which-will-it-be-opera-firefox-ie/" title="Which will it be ? Opera ? Firefox ? IE ? (June 13, 2008)">Which will it be ? Opera ? Firefox ? IE ?</a> (38)</li>
	<li><a href="http://www.ghacks.net/2009/03/13/web-browser-firefox-31-beta-3/" title="Web Browser: Firefox 3.1 Beta 3 (March 13, 2009)">Web Browser: Firefox 3.1 Beta 3</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/01/new-attack-combine-files-with-jar-scripts/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
