All I need Java for is ....
Java just can't catch a break! A number of our readers have pointed out that Security Explorations claims they have 2 new Java zero days (no verification from Oracle on this yet).
This of course has fueled the fire of "it's time to just say no and uninstall Java" in many quarters. And for general purpose internet browsing, maybe you can. If you do need Java, and if you do, changing the security settings to "ask every time" is a good way to go. Of course, if you run a business app that needs Java, you need to make it transparent to your user community somehow - this can be particular problem if your app needs a specific (aka old / vulnerable) Java version - we've talked about this in a few different stories over the last few months.
But this got me to thinking, as security folks, what tools or processes do we use daily that need Java?
My list is pretty short:
Burp Suite for Web Assessments - www.portswigger.net
ZAP - Zed Attack Proxy, also for Web Assessments - https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project
Nessus, for straight up vulnerability assessments and security scans (Java is only needed for PDF exports in Nessus I think) - http://www.tenable.com
Network appliance administration is often Java based as well - for instance, the GUI for Cisco ASA firewalls and many wirelss controllers requires Java to run.
What's in your "I only need Java for this or that infosec tool" list? Please, let us know through our comment form.
============ Update ============
Our friends at PaulDotCom tell us (in the comments below) that Nessus no longer needs Java for PDF exports, as of November of 2012
Thanks for the heads-up on that, my bad for not noticing the change when it came !
===============
Rob VandenBrink
Metafore
Comments
techvet
Feb 26th 2013
1 decade ago
Eclipse
Vigiliti nLive
Freemind
jrivett
Feb 26th 2013
1 decade ago
Cisco SSL vpn client
Juniper SSL vpn client
Zyxel SSL vpn client
I use QuickJava in Firefox to enable/disable on the fly. Every chance I get, I beg vendors to develop in another language . . .
RichH
Feb 26th 2013
1 decade ago
http://www.libreoffice.org/download/system-requirements/
matteo
Feb 26th 2013
1 decade ago
Ref: http://static.tenable.com/documentation/nessus_5.0_installation_guide.pdf
PaulDotCom
Feb 26th 2013
1 decade ago
I use Java for Oracle apps (we've a dozen), Cisco ASDM Firewall configuration, HP iLO.
I was able to uninstall Java from my personal computer when my small credit union updated their banking app's menu system to not need Java.
For each environment, I have multiple browsers and use "-no-remote -ProfileManager" with Firefox to get prompted for which one to use even if there is already a Firefox session running. My personal computer only had Java enabled in my banking browser profile. My work computer only has Java enabled in my Internal-only profile.
This isn't something you call really get non-technical people to buy off on or understand. The best thing we do is block Internet Explorer access to the Internet (user-agent string blocking in Proxy) and only allow Java with it. Firefox is all that is allowed to the Internet and using GPOs we block Java with Firefox. So, Internet Explorer for intranet-only, Firefox for Internet (no Java, and most of our staff have to use an Oracle app or two or dozen).
Jason R
Feb 26th 2013
1 decade ago
kirk
Feb 26th 2013
1 decade ago
http://www.elkproducts.com/product-catalog/elk-m1xep-m1-ethernet-interface
Not used every day, but it sure is handy when it's needed.
datadog
Feb 26th 2013
1 decade ago
Erik
Feb 26th 2013
1 decade ago
TG
Feb 26th 2013
1 decade ago