Vulnerability Development mailing list archives
Re: Java - JRE, SDK Java Web Start
From: Kish Pent <kish_pent () yahoo com>
Date: Tue, 17 Jul 2007 10:57:36 -0700 (PDT)
Good question, first off :) Hey Jfvanmeter,
How does everyone feel about java being installed by vendors in a propriety path i.e. program files\mysoftware\bin\jre\1.4.0\ and never patching it.
I ran an enterprise scan to looking for javaws.exe and found it in 175 unique paths. Should they be held accountable for the patching of java when they install it?
Indeed, the person who installs is accountable for it, provided the SLA says so. ;) Say if they provide support/after-sale support or something along those lines, then they're supposed to patch/install updates regularly.
I had one vendor who installed java 1.3 and 1.4, and when I ask them about it. There statement was you dont have the modules that require those versions you can just delete them
Tell them, that "This is the dumbest thing I've ever heard" in all of my computing career. ;)
How does everyone patch Java that is not installed in its default location?
AFAIK, it doesn't matter whether you install in your root drive or not. All that matters is you patch it, and the patch will be designed by Sun mostly to work in almost all conditions, or else, this would be a big deal to debate on, in their mailing list. PS: How this patch thing works is, it retrieves your settings/install settings from windows registry, before it even starts to go further. Since you just press update/or next->next->finish, you can't see this going on in the background. Cheers :) Kish Kishore Penetration Tester Smart Security T.Nagar , Chennai Phone: 91 98841 80767 ____________________________________________________________________________________ Looking for earth-friendly autos? Browse Top Cars by "Green Rating" at Yahoo! Autos' Green Center. http://autos.yahoo.com/green_center/
Current thread:
- Java - JRE, SDK Java Web Start jfvanmeter (Jul 17)
- Re: Java - JRE, SDK Java Web Start Kish Pent (Jul 17)
- Re: Java - JRE, SDK Java Web Start Blue Boar (Jul 17)
- Re: Java - JRE, SDK Java Web Start 3APA3A (Jul 18)
- <Possible follow-ups>
- Re: Java - JRE, SDK Java Web Start jfvanmeter (Jul 18)