<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://wiki.apidesign.org/skins/common/feed.css?116"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Malware - Revision history</title>
		<link>http://wiki.apidesign.org/index.php?title=Malware&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.12.0rc1</generator>
		<lastBuildDate>Sat, 18 Apr 2026 04:49:29 GMT</lastBuildDate>
		<item>
			<title>JaroslavTulach: /* Maven &amp; Apache NetBeans 12 */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10122&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Maven &amp;amp; Apache NetBeans 12&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 09:03, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released [[Apache]] [[NetBeans]] 12 to the rescue! First &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;an &lt;/del&gt;foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds. However, should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released [[Apache]] [[NetBeans]] 12 to the rescue! First &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;and &lt;/ins&gt;foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds. However, should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] for [[Maven]] ever seen!&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] for [[Maven]] ever seen!&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 09:03:14 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Popularity is Popularity */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10121&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Popularity is Popularity&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 08:03, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Popularity is Popularity ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Popularity is Popularity ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;On the other hand, [[I]] haven't noticed such amount of buzz about [[NetBeans]] for a long time. Even negative popularity is a popularity and [[I]] enjoy reading description of the virus attack against the [[Ant]] build files written down by [[NetBeans]] from independent researchers! Moreover, as the researchers noted, ''It was interesting that this malware attacked the [[NetBeans]] build process specifically since it is not the most common Java IDE in use today''. True, [[NetBeans]] is no longer hot and it is fair to ask why did the attackers choose [[NetBeans]]? My favorite explanation is that it was a ''targeted attack'' - an attack against somebody who was known to use [[NetBeans]] to develop some application using [[Ant]] based projects generated by [[NetBeans]]. Might it be a student's prank against roommates? Might it be more serious?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;On the other hand, [[I]] haven't noticed such amount of buzz about [[NetBeans]] for a long time. Even negative popularity is a popularity and [[I]] &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;really &lt;/ins&gt;enjoy reading description of the virus attack against the [[Ant]] build files written down by [[NetBeans]] from independent researchers! Moreover, as the researchers noted, ''It was interesting that this malware attacked the [[NetBeans]] build process specifically since it is not the most common Java IDE in use today''. True, [[NetBeans]] is no longer hot and it is fair to ask why did the attackers choose [[NetBeans]]? My favorite explanation is that it was a ''targeted attack'' - an attack against somebody who was known to use [[NetBeans]] to develop some application using [[Ant]] based projects generated by [[NetBeans]]. Might it be a student's prank against roommates? Might it be more serious?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;In any case it is clear, the malware developers could easily use the same attack vector against ''Make'', [[Gradle]] and even [[Maven]]. The chances to spread the virus would be even higher given the dominance of these build systems over [[Ant]]. All that is needed is to locate sources of ''Makefile'', ''build.gradle'' and ''pom.xml'' and mangle them a bit to execute malicious code. In addition to that one can modify the locally cached [[JAR]] files in ''$HOME/.m2/repository'' directory &amp;amp; co. just like the octopus malware did for the [[Ant]] based projects.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;In any case it is clear, the malware developers could easily use the same attack vector against ''Make'', [[Gradle]] and even [[Maven]]. The chances to spread the virus would be even higher given the dominance of these build systems over [[Ant]]. All that is needed is to locate sources of ''Makefile'', ''build.gradle'' and ''pom.xml'' and mangle them a bit to execute malicious code. In addition to that one can modify the locally cached [[JAR]] files in ''$HOME/.m2/repository'' directory &amp;amp; co. just like the octopus malware did for the [[Ant]] based projects.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 08:03:07 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Maven &amp; Apache NetBeans 12 */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10120&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Maven &amp;amp; Apache NetBeans 12&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:41, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released [[Apache]] [[NetBeans]] 12 to the rescue! First an foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds, &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;but &lt;/del&gt;should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released [[Apache]] [[NetBeans]] 12 to the rescue! First an foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;. However&lt;/ins&gt;, should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] for [[Maven]] ever seen!&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] for [[Maven]] ever seen!&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:41:52 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Vulnerable Build Systems */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10119&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Vulnerable Build Systems&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:40, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 13:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 13:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Vulnerable Build Systems ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Vulnerable Build Systems ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The current build systems pay little attention to security. Everyone shall be aware that by running a build one is executing a potentially untrusted code. The build systems themselves provide no isolation by itself, the best one can do is to create a virtually isolated environment to perform the build from scratch and throw the results away after that. However, the situation may be even tougher, certain build systems (and their IDE integration) may trigger the untrusted code even when you are inspecting the code - e.g. even without starting the build. [[I]] have described this flaw in my article where I claimed that [[Gradle|Gradle belongs to the Ant age!]] &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;- in &lt;/del&gt;order to assemble a classpath (a prerequisite to editing [[Java]] sources) the [[IDE]] has to execute ''build.gradle'' which can do anything! When I wrote the article [[Gradle]] guys couldn't understand why having a [[Turing complete]] build system is wrong. &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;But &lt;/del&gt;I assume they get it one day...&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The current build systems pay little attention to security. Everyone shall be aware that by running a build one is executing a potentially untrusted code. The build systems themselves provide no isolation by itself, the best one can do is to create a virtually isolated environment to perform the build from scratch and throw the results away after that. However, the situation may be even tougher, certain build systems (and their IDE integration) may trigger the untrusted code even when you are inspecting the code - e.g. even without starting the build. [[I]] have described this flaw in my article where I claimed that [[Gradle|Gradle belongs to the Ant age!]] &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;In &lt;/ins&gt;order to assemble a classpath (a prerequisite to editing [[Java]] sources) the [[IDE]] has to execute ''build.gradle'' which can do anything! When I wrote the article [[Gradle]] guys couldn't understand why having a [[Turing complete]] build system is wrong. &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;I&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;assume they get it one day...&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:40:33 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Popularity is Popularity */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10117&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Popularity is Popularity&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:36, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 9:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 9:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;On the other hand, [[I]] haven't noticed such amount of buzz about [[NetBeans]] for a long time. Even negative popularity is a popularity and [[I]] enjoy reading description of the virus attack against the [[Ant]] build files written down by [[NetBeans]] from independent researchers! Moreover, as the researchers noted, ''It was interesting that this malware attacked the [[NetBeans]] build process specifically since it is not the most common Java IDE in use today''. True, [[NetBeans]] is no longer hot and it is fair to ask why did the attackers choose [[NetBeans]]? My favorite explanation is that it was a ''targeted attack'' - an attack against somebody who was known to use [[NetBeans]] to develop some application using [[Ant]] based projects generated by [[NetBeans]]. Might it be a student's prank against roommates? Might it be more serious?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;On the other hand, [[I]] haven't noticed such amount of buzz about [[NetBeans]] for a long time. Even negative popularity is a popularity and [[I]] enjoy reading description of the virus attack against the [[Ant]] build files written down by [[NetBeans]] from independent researchers! Moreover, as the researchers noted, ''It was interesting that this malware attacked the [[NetBeans]] build process specifically since it is not the most common Java IDE in use today''. True, [[NetBeans]] is no longer hot and it is fair to ask why did the attackers choose [[NetBeans]]? My favorite explanation is that it was a ''targeted attack'' - an attack against somebody who was known to use [[NetBeans]] to develop some application using [[Ant]] based projects generated by [[NetBeans]]. Might it be a student's prank against roommates? Might it be more serious?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;In any case it is clear, the malware developers could easily use the same attack vector against &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/del&gt;Make&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;]]&lt;/del&gt;, [[Gradle]] and even [[Maven]]. The chances to spread the virus would be even higher given the dominance of these build systems over [[Ant]]. All that is needed is to locate sources of ''Makefile'', ''build.gradle'' and ''pom.xml'' and mangle them a bit to execute malicious code. In addition to that one can modify the locally cached [[JAR]] files in ''$HOME/.m2/repository'' directory &amp;amp; co. just like the octopus malware did for the [[Ant]] based projects.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;In any case it is clear, the malware developers could easily use the same attack vector against &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;''&lt;/ins&gt;Make&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;''&lt;/ins&gt;, [[Gradle]] and even [[Maven]]. The chances to spread the virus would be even higher given the dominance of these build systems over [[Ant]]. All that is needed is to locate sources of ''Makefile'', ''build.gradle'' and ''pom.xml'' and mangle them a bit to execute malicious code. In addition to that one can modify the locally cached [[JAR]] files in ''$HOME/.m2/repository'' directory &amp;amp; co. just like the octopus malware did for the [[Ant]] based projects.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Vulnerable Build Systems ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Vulnerable Build Systems ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:36:44 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Vulnerable Build Systems */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10116&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Vulnerable Build Systems&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:35, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 13:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 13:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Vulnerable Build Systems ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Vulnerable Build Systems ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The current build systems pay little attention to security. Everyone shall be aware that by running a build one is executing a potentially untrusted code. The build systems themselves provide no isolation by itself, the best one can do is to create a virtually isolated environment to perform the build from scratch and throw the results away after that. However, the situation may be even tougher, certain build systems (and their IDE integration) may trigger the untrusted code even when you are inspecting the code - e.g. even without starting the build. [[I]] have described this flaw in my article where I claimed that [[Gradle|Gradle belongs to the Ant age!]] - in order to assemble a classpath (a prerequisite to editing [[Java]] sources) the [[IDE]] has to execute ''build.gradle'' which can do anything! When I wrote the article [[Gradle]] guys couldn't understand why having a [[Turing &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Complete&lt;/del&gt;]] build system is wrong. But I assume they get it one day...&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The current build systems pay little attention to security. Everyone shall be aware that by running a build one is executing a potentially untrusted code. The build systems themselves provide no isolation by itself, the best one can do is to create a virtually isolated environment to perform the build from scratch and throw the results away after that. However, the situation may be even tougher, certain build systems (and their IDE integration) may trigger the untrusted code even when you are inspecting the code - e.g. even without starting the build. [[I]] have described this flaw in my article where I claimed that [[Gradle|Gradle belongs to the Ant age!]] - in order to assemble a classpath (a prerequisite to editing [[Java]] sources) the [[IDE]] has to execute ''build.gradle'' which can do anything! When I wrote the article [[Gradle]] guys couldn't understand why having a [[Turing &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;complete&lt;/ins&gt;]] build system is wrong. But I assume they get it one day...&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:35:51 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Maven &amp; Apache NetBeans 12 */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10115&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Maven &amp;amp; Apache NetBeans 12&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:35, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 19:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 19:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released [[Apache]] [[NetBeans]] 12 to the rescue! First an foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds, but should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released [[Apache]] [[NetBeans]] 12 to the rescue! First an foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds, but should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;form &lt;/del&gt;[[Maven]] &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you have &lt;/del&gt;ever seen!&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;for &lt;/ins&gt;[[Maven]] ever seen!&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:35:06 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Don't Blame the Editor! */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10114&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Don't Blame the Editor!&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:31, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 3:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Don't Blame the Editor! ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Don't Blame the Editor! ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[I]] have to admit I am not sure I should be ashamed or happy? Helping spreading viruses isn't really something one should be proud of, but at the end [[NetBeans]] IDE itself is quite innocent here. The attack doesn't use the [[NetBeans]] code itself, it just modifies the [[Ant]] build files written down by the IDE. It knows the layout of the files, it knows their structure and knows what to modify to spread itself. Blaming [[NetBeans]] for that is just like blaming your ''Makefile'' editor for saving files that get later modified and do a harm your computer. The problem isn't the IDE nor the editor, the problem is that the developer has allowed an untrusted code to run on own computer and modify local executable files.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[I]] have to admit I am not sure I should be ashamed or happy? Helping spreading viruses isn't really something one should be proud of, but at the end [[NetBeans]] IDE itself is quite innocent here. The attack doesn't use the [[NetBeans]] code itself, it just modifies the [[Ant]] build files written down by the IDE. It knows the layout of the files, it knows their structure and knows what to modify to spread itself. Blaming [[NetBeans]] for that is just like blaming your ''Makefile'' editor for saving files that get later modified and do a harm &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;to &lt;/ins&gt;your computer. The problem isn't the IDE nor the editor, the problem is that the developer has allowed an untrusted code to run on own computer and modify local executable files.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Popularity is Popularity ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Popularity is Popularity ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:31:01 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Maven &amp; Apache NetBeans 12 */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10113&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Maven &amp;amp; Apache NetBeans 12&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:28, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 17:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Maven &amp;amp; Apache NetBeans 12 ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released Apache NetBeans 12 to the rescue!&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;Let's download just (about to be) released &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;Apache&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;]] [[&lt;/ins&gt;NetBeans&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;12 to the rescue&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;! First an foremost [[NetBeans]] 12 supports [[Maven]] based projects out of the box - e.g. when you create new project, it is no longer [[Ant]] based, but [[Maven]] based. [[NetBeans]] still recognizes the [[Ant]] based projects, as well as [[Gradle]] based projects, but because of the [[declarative]] format of [[Maven]] and the ability of [[NetBeans]] to deduce classpath &amp;amp; co. without executing a single line of [[Maven]] code, we have decided to standardize around [[Maven]]. Developers still have to be careful when executing their [[Maven]] builds, but should an attack against that appear in the future, there is not going to be anything [[NetBeans]] specific in it.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Download [[Apache]] [[NetBeans]] 12 - the best [[UI]] form [[Maven]] you have ever seen&lt;/ins&gt;!&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:28:32 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
		<item>
			<title>JaroslavTulach: /* Popularity is Popularity */</title>
			<link>http://wiki.apidesign.org/index.php?title=Malware&amp;diff=10112&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Popularity is Popularity&lt;/span&gt;&lt;/p&gt;

			&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;tr&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 07:08, 1 June 2020&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 7:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Popularity is Popularity ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== Popularity is Popularity ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;On the other hand, [[I]] haven't noticed such amount of buzz about [[NetBeans]] for a long time. Even negative popularity is a popularity and [[I]] enjoy reading description of the virus attack against the [[Ant]] build files written down by [[NetBeans]] from independent researchers! Moreover, as the researchers noted, ''It was interesting that this malware attacked the [[NetBeans]] build process specifically since it is not the most common Java IDE in use today''. True, [[NetBeans]] is no longer hot and it is fair to ask why did the attackers choose [[NetBeans]]? My favorite explanation is that it was a ''targeted attack'' - an attack against somebody who was known to use [[NetBeans]] to develop some application using [[Ant]] based projects generated by [[NetBeans]]. Might it &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;have been &lt;/del&gt;a student's prank against roommates? Might it be more serious?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;On the other hand, [[I]] haven't noticed such amount of buzz about [[NetBeans]] for a long time. Even negative popularity is a popularity and [[I]] enjoy reading description of the virus attack against the [[Ant]] build files written down by [[NetBeans]] from independent researchers! Moreover, as the researchers noted, ''It was interesting that this malware attacked the [[NetBeans]] build process specifically since it is not the most common Java IDE in use today''. True, [[NetBeans]] is no longer hot and it is fair to ask why did the attackers choose [[NetBeans]]? My favorite explanation is that it was a ''targeted attack'' - an attack against somebody who was known to use [[NetBeans]] to develop some application using [[Ant]] based projects generated by [[NetBeans]]. Might it &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;be &lt;/ins&gt;a student's prank against roommates? Might it be more serious?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;In any case it is clear, the malware developers could easily use the same attack vector against [[Make]], [[Gradle]] and even [[Maven]]. The chances to spread the virus would be even higher given the dominance of these build systems over [[Ant]]. All that is needed is to locate sources of ''Makefile'', ''build.gradle'' and ''pom.xml'' and mangle them a bit to execute malicious code. In addition to that one can modify the locally cached [[JAR]] files in ''$HOME/.m2/repository'' directory &amp;amp; co. just like the octopus malware did for the [[Ant]] based projects.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;In any case it is clear, the malware developers could easily use the same attack vector against [[Make]], [[Gradle]] and even [[Maven]]. The chances to spread the virus would be even higher given the dominance of these build systems over [[Ant]]. All that is needed is to locate sources of ''Makefile'', ''build.gradle'' and ''pom.xml'' and mangle them a bit to execute malicious code. In addition to that one can modify the locally cached [[JAR]] files in ''$HOME/.m2/repository'' directory &amp;amp; co. just like the octopus malware did for the [[Ant]] based projects.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 01 Jun 2020 07:08:00 GMT</pubDate>			<dc:creator>JaroslavTulach</dc:creator>			<comments>http://wiki.apidesign.org/wiki/Talk:Malware</comments>		</item>
	</channel>
</rss>