Most Recent Posts
New Feature?
by ChrisFNP - 04/22/2025 6:37 PM
Here is a new one
by ChrisFNP - 04/22/2025 6:20 PM
AC Version 12.3
by ChrisFNP - 04/22/2025 5:18 PM
I won't get help because I am I
by Bert - 04/22/2025 9:09 AM
An automated process failed: MedsUdates
by ChrisFNP - 04/15/2025 10:12 AM
Pharmacy Request Counter Issues
by Headcase - 04/08/2025 7:04 PM
phantom printer
by imcffp - 04/08/2025 10:26 AM
AC v12 mandatory upgrade
by ChrisFNP - 04/01/2025 9:47 AM
Member Spotlight
jimmie
jimmie
Montana
Posts: 1,612
Joined: October 2011
Newest Members
It's me, Paradise Family, MedCode, MZ Medical Billi, girlfromwebpage
4,593 Registered Users
Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Jun 2009
Posts: 1,811
Indy Offline OP
Member
OP Offline
Member
Joined: Jun 2009
Posts: 1,811
Since this is perceived by security folks as high risk, I'm posting this in the General Discussion area.

http://allthingsd.com/20111202/why-today-is-a-very-good-day-to-update-java-on-your-computer/

a pull quote:
"Consider yourself warned: Today is a very good day to update the version of Java running on your computer. This applies to you whether you run Windows, Mac OS X or Linux. If you?ve noticed your machine suggesting that you update Java, do it right away.

The reason? A scary vulnerability in Java that was detected over the summer, and which Oracle has subsequently fixed, is being exploited by people who create the malware and crimeware that causes so many headaches for home users and corporate IT departments."

This is going on the top of the list for our maintenance this weekend.



Indy
"Boss"

Indy's Blog

www.BestForYourPractice.com
Our Name is Our Creed
Joined: Sep 2009
Posts: 2,982
Likes: 5
JBS Online Content
Member
Online Content
Member
Joined: Sep 2009
Posts: 2,982
Likes: 5
Indy,
Thanks for the heads-up. Somehow it seems that we are doing a Java update every other day, anyway. If only Windows and AC updates were as easy as Java...


Jon
GI
Baltimore

Reduce needless clicks!
Joined: Jun 2009
Posts: 1,811
Indy Offline OP
Member
OP Offline
Member
Joined: Jun 2009
Posts: 1,811
Just an update now that I have seen a machine with the attack in a production environment.

When you do the "Verify Java" step, in some cases there will come up a small notification in the text that there are vulnerable versions still on the machine that need to be installed.

The attacks are specifically calling previous vulnerable Java versions, so they need to be removed as well as installing the latest version [currently 6 v30].

Soooo .. take the time to follow the link to see the versions you need to remove, then open up your Control Panel, Add/Remove Programs, and remove the vulnerable versions of Java.

In this particular machine, it was one of the first done, I missed the dialog the first time, so it was attacked. Sophos caught it, reported it to the Management Server, and I used the Management Server to finish the cleanup remotely.

Everything worked the first time other than the operator who missed the dialog. nothing like layered protection.


Indy
"Boss"

Indy's Blog

www.BestForYourPractice.com
Our Name is Our Creed
Joined: Feb 2011
Posts: 679
Likes: 1
Member
Offline
Member
Joined: Feb 2011
Posts: 679
Likes: 1
Indy,
I did the Java update as you suggested, thanks for the heads up.

The is also Java Runtime environment in the list; is that something that gets updated?

Donna


Donna
Joined: Dec 2009
Posts: 1,197
Likes: 8
Member
Offline
Member
Joined: Dec 2009
Posts: 1,197
Likes: 8


James Summerlin
My personal site: http://www.dataintegrationsolutions.net
james@dataintegrationsolutions.net
Joined: Nov 2006
Posts: 2,084
Member
Offline
Member
Joined: Nov 2006
Posts: 2,084
The latest version of Java for the Windows OS is Version 6 Update 30. You can see what version of Java your computer is running here. All versions of Java can be downloaded here.

Be observant when clicking through the several windows when installing Java. There is an option to install the "Ask Toolbar" on your browser, marked "yes" by default. Be sure to click off the checkbox before installing.


John
Internal Medicine
Joined: Feb 2011
Posts: 679
Likes: 1
Member
Offline
Member
Joined: Feb 2011
Posts: 679
Likes: 1
I am still a little confused.
I have installed the latest version, and then when I go back to Add/Remove programs, this is what I see:

J2SE Runtime Environment 5.0 update 16

Java(TM) 6 update 30

Is the top one an old version that should be removed?
Is there anything that would depend on an old version to run?

Donna


Donna
Joined: Nov 2006
Posts: 2,084
Member
Offline
Member
Joined: Nov 2006
Posts: 2,084
The Java Runtime Environment (JRE) is created on your computer when you download Java software. The JRE consists of the Java Virtual Machine (JVM) & Java platform core classes and libraries. The Java Plug-in software (which is what Indy is suggesting be updated) is a component of the Java Runtime Environment (JRE). The JRE allows applets written in the Java programming language to run inside various browsers.


John
Internal Medicine
Joined: Jun 2009
Posts: 1,811
Indy Offline OP
Member
OP Offline
Member
Joined: Jun 2009
Posts: 1,811
Donna,

When you run the Java verification there is a link that will indicate which versions of the Java updates that are vulnerable and should be un-installed. It often varies from machine to machine as different machines will often have Java installed at different times and versions.

The other thing that makes this more confusing is that the Java nomenclature has changed over time. There is a story behind it, but probably not of interest.

On several machines I have seen version 5 update 1 [ and others in version 5] tagged, and several of the earlier version 6 [IIRC including 1,5,6,7,11]. Since the Java Applet runs during verify, it will tag the versions you want to uninstall - I'd leave that browser window up and toggle between that and the add-remove programs.

When this all started it was Java 6 v29, we are now already to 6 v30 as mentioned above.


Indy
"Boss"

Indy's Blog

www.BestForYourPractice.com
Our Name is Our Creed
Joined: Jun 2009
Posts: 1,811
Indy Offline OP
Member
OP Offline
Member
Joined: Jun 2009
Posts: 1,811
Donna,

And for the record, I'll be cheering the Ravens on today, San Diego fans are weak sauce.


Indy
"Boss"

Indy's Blog

www.BestForYourPractice.com
Our Name is Our Creed
Joined: Feb 2011
Posts: 679
Likes: 1
Member
Offline
Member
Joined: Feb 2011
Posts: 679
Likes: 1
Thanks, John and Indy!

Good choice, Indy. There will be lots of tired folks here in Baltimore tomorrow after the late game tonight. Go Ravens!


Donna
Indy #38846 12/19/2011 4:41 PM
Joined: Mar 2005
Posts: 241
Member
Offline
Member
Joined: Mar 2005
Posts: 241
Originally Posted by Indy
Donna,

And for the record, I'll be cheering the Ravens on today, San Diego fans are weak sauce.

The fans may be weak, but they were not playing :^)
Where has that Chargers team been the rest of the year :^(
But we are still in the hunt for a playoff berth.

Greg

Indy #38847 12/19/2011 4:46 PM
Joined: Jul 2010
Posts: 869
Member
Offline
Member
Joined: Jul 2010
Posts: 869
Go Chargers! I was at that game. For once the Chargers had a decent game. Baltimore was favored to win too.

Playoff hopes are still slim. Need some help from other teams!

Indy, thought you would be a Charger fan based on your proximity?


Marty
Physician Assistant
Fullerton, CA
Indy #38851 12/19/2011 7:01 PM
Joined: Feb 2011
Posts: 679
Likes: 1
Member
Offline
Member
Joined: Feb 2011
Posts: 679
Likes: 1
Grrrr....
That game was definitely not what we expect from our Ravens!
Especially in a season where we have defeated Pittsburgh twice.


Donna
Indy #38853 12/19/2011 8:08 PM
Joined: Jul 2010
Posts: 869
Member
Offline
Member
Joined: Jul 2010
Posts: 869
Your Ravens hadn't allowed anyone to score on first possession in a long time. Chargers scored on their first five possessions. I really thought the Raven's Defense was going to squash the Chargers.



Marty
Physician Assistant
Fullerton, CA
Joined: Jun 2009
Posts: 1,811
Indy Offline OP
Member
OP Offline
Member
Joined: Jun 2009
Posts: 1,811
Originally Posted by Greg Phillips
Originally Posted by Indy
Donna,

And for the record, I'll be cheering the Ravens on today, San Diego fans are weak sauce.

The fans may be weak, but they were not playing :^)
Where has that Chargers team been the rest of the year :^(
But we are still in the hunt for a playoff berth.

Greg

Greg,

You sound like a real fan, and I know Marty, so no disrespect meant. From when I was based in San Diego and later, I found many SD fans to be fair-weather only.

.... and yes, you really should update your Java AND uninstall the vulnerable versions.


Indy
"Boss"

Indy's Blog

www.BestForYourPractice.com
Our Name is Our Creed
Indy #38865 12/20/2011 1:57 PM
Joined: Jul 2010
Posts: 869
Member
Offline
Member
Joined: Jul 2010
Posts: 869
Indy,

No disrespect taken. I've only been a Charger fan for the last 9 years or so. From their history, I missed out on the really bad years. The year before I bought season tickets, the team only won one game the whole year. Imagine it was painful to be a Charger fan (actually still is...ha ha)

Happy Holidays to you!


Marty
Physician Assistant
Fullerton, CA

Moderated by  ChrisFNP, DocGene, JBS, Wendell365 

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Who's Online Now
0 members (), 86 guests, and 22 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
ffac 6
koby 5
imcffp 5
JBS 3
Bert 2
tcosta 2
Top Posters
Bert 12,873
JBS 2,982
Wendell365 2,363
Sandeep 2,316
ryanjo 2,084
Leslie 2,002
Wayne 1,889
This board is dedicated to the memory of Michael "Indy" Astleford. February 6, 1961 -- April 16, 2019




SiteLock
Powered by UBB.threads™ PHP Forum Software 7.7.5