Blocked JAVA Plug-in when using Safari to access a JAVA enabled chart via Safari
Hello, For the past 24 hours, a site that I use on a regular basis blocks a JAVA plug-in when trying to open a page supposed to show a chart. Has anyone run into that same situation? Thanks.
Posted on Jan 11, 2013 5:55 PM
You installed the Oracle Java 7 plugin, which is insecure and has been blocked by Apple. To revert to the Java 6 plugin, follow these instructions:
Posted on Jan 11, 2013 8:18 PM
Linc is partically right, that may get you working again, but know that that also puts your computer at risk of compromise. You’re effectively downgrading to an unsuporrted and less secure version of Java. You’re side-stepping the protections of XProtect, which is Apple’s way to help protect customers against active security risks that are targeting the Safari browser and associated plugins.
It is not that you installed an insecure version — and Apple blocked it — the problem is that *all* versions of Java are currently insecure, and Java 6 is far less secure than Java 7.
The worst thing you can do for your security is to downgrade to an even less secure and unsupported software product — Oracle is working on a patch for Java now, by the way.
There are a couple of options, but you have to weigh them against the risks. The reason for the change was to protect users, afterall.
One option is to use some of the online hints to go back to Java 6 — that is a horrific idea and puts your system at the greatest risk. It’s like a Windows user going from an up to date copy of Windows 7 back to Windows XP. Or going from Mountain Lion to Panther. Going backwards is almost never a solution for security — but it will allow you to run Java plugins again.
Another option is to manually modify XProtect in Safari to accept the 1.7.10r18 version as valid. This is also risky because there are active exploits in the wild for this version of Java. That is the reason for Apple’s change this week — there were several exploits shown to work, and work against Macs running Java 7. I’m not sure how often XProtect does its thing, but, if you manually modify the plist, you may have to do so repeatedly.
You can also run the developer version of Java, which is 1.7.12 — I don’t believe this has a *fix* for the exploit that is currently being used, but, it will fool Safari into thinking you are running a newer version thatn 1.7.10r18.
Your final option is to wait. Oracle will likely update soon. If you really need Java, you can probably use Firefox and 1.7.10r18, but you still are running a risk of having your system compromised.
If you are diligent and only enable Java 6 when you access a particular and very well trusted Java based site/applicaiton, and disable it when you’re not needing it, you may be okay — but keep in mind that the security weakness that breaks in Java 7 from this week is *also* present in Java 6. and you’ll have to deal with all of the Java 6 based security issues as well.
It’s a tough call, and entirely a personal one for you and the risks you consider to be acceptable to your computing environment.
How to re — activate a blocked Java Plugin?
First of all, let me explain. I work in a supporting role for a company that uses some element of management systems to monitor and troubleshoot network problems. Due to safety and the application of our enterprise support policies, we are forced to use a version of Firefox and Java to access the Web server of the EMS.
The problem:
With the recent update to Mozilla blocking, the version of Java policies we use is blocked and access to the site no longer works correctly. We need a workaround method that will allow us to get around the block.
Hey creation: we actively and voluntarily recognize the risks that are inherent in stocks such as I ask. I would ask that discussion on the subject that we need an immediate solution to access our tool and a long term solution — safe — will be concocted with the help of our business processes.
I am pleased to provide you with all the details that may be necessary.
Thank you!
EDIT: I solved the problem myself: see answer below.
I solved it. Proceed at your own risk
- Open a new tab
- Go to Subject: config
- Accept the security warning
- Replace extensions.blocklist.enabled to false
- Restart the browser
This prevents the verification of the red list that you have configured to extensions.blocklist.detailsURL firefox
Similar Questions
- Firefox keeps blocking Java plugins, I’ve updated several times, but the problem persists «VLC media player Web Plugin 2.1.3» update now don’t workr I’ve updated the VLC media player a dozen times in the last week or two, but it continues to not work, with a message from Firefox to come saying «Web PluginVLC Web Plugin 2.1.3 vulnerable 2.1.3.0 VLC media player update now». All other plugins seem to now, Firefox said recently that many of them had recently updated and all the others worked.
Almost all the websites that I visit comes up with a message saying that the plugin is obsolete and has been blocked and I think maybe I should just give up Firefox and use another browser. Yes, it would be wise to delete this program VLC. - How can I activate the pop-up Blocker How can I activate the blocker pop up on Firefox? drummershob said
- Open Internet Explorer, click on the «Tool» button in the menu bar, click ‘Internet Options’ and then select the security»» tab.
- Select the ‘Internet’ zone, select «Custom level» and go to the «Security settings — Internet Zone» box.
- Click the checkbox enable «Active Scripting» under the Scripting section, and then click the OK button to apply the settings. Restart your browser when you have finished to apply the settings and enable JavaScript.
Chrome (for the old version, but could be similar):
I found a metalink document 433862.1 describing how to implement custom OVD Java plugin, it is for the version 10.1.4 and use it OVDM to do, but I can’t find OVDM in the 11.1.1.1.0 version, I don’t miss something?
You can use this button to go to the Firefox profile folder:
Is it possible to use a specific form a specific Java Plugin? This, of course, in the same session, in the same browser.
For example:
Use of the form formA.fmx, the Java plug-in 1.6.0_20
Use of the form formB.fmx, the Java plug-in 1.5.0_06
With respect, There was focus (zorder) of window problems reported long since 1.6.0_10 was released. Some were considered JRE issues and other matters of forms and some are still being investigated. In this spirit, I would recommend using 11.1.1.4 or 11.1.2 If you’re not already do. This will ensure that you have the latest patches available in place. Also helpful is disabling JRE ‘Next generation’ option. This setting is found on the Advanced tab of the control panel of the JRE. Uncheck this box and see if the behavior is more to your liking.
Maybe you are looking for
- Satellite L50 — USB connectivity problem Hello, new to these forums and just buy a Toshiba Satellite L50. The problem is when I connect my iPhone in a few seconds it will disconnect, reconnect, disconnect plug. Then a pop up according to sleep and fresh loan, then another pop up will say ch
- BT’s unknown devices in Device Manager Hello I saw some unknown bluetooth devices in my device manager. All my drivers are up to date. Missing features- Spoiler (Highlight to read) Driver Bluetooth installed- Spoiler (Highlight to read) Thank you HDash_Tech
- Desktop HP Pavilion 500-314: DVI Port defective? I have two monitors that I use for my photography business and I just opned my new HP pluged while with the exception of port DVI does not except my DVI connector. When I looked closer, I could see that the port has all the holes of pin except for th
- 3 questions about encryption on the Z5 Hi, I have three questions to ask other Xperia users. If I decide to encrypt my phone (Z5): (1) what will be the star of the performance? It will be noticeable? (2) I know it is not compatible with the smart lock, but it will make it also impossible
- Random BSOD associated NETIO SYSTEM_SERVICE_EXCEPTION. SYS Hello world Since January of this year I’ve known BSOD at random times. I was not able to determine anything that these accidents could have in common, with the exception of the fact that my laptop is always connected to a wifi network. I had an acci