Java Deployment with JNLP and WebStart by Mauro Marinilli

ISBN: 0672321823, 9780672321825
Publisher: Sams
Page: 393
Format: pdf

There are many tutorials out there that show how to deploy a simple application with Java Web Start. But when I first started with the automated option in Netbeans to launch the project with Java Web Start. Reports indicate this vulnerability is being actively exploited, and exploit code is publicly available. Take care to disable both the Java and Java Deployment Toolkit plug-ins and, if necessary, disable Java Web Start by breaking JNLP handling. You specify all requirements for your application in the JNLP file, and off you go. Java Web Start is primarily designed for application deployment. Note that all the jar in the lib folder need to be listed to avoid any security issues. My JNLP (called test.jnlp) file looks like this. Not only Deploying the application. By convincing a user to load a malicious Java applet or Java Network Launching Protocol (JNLP) file, an attacker could execute arbitrary code on a vulnerable system with the privileges of the Java plug-in process. The Java Deployment Toolkit plug-in and Java Web Start can also be used as attack vectors. Is there a migration path from applets to applications? Any web browser using the Java 7 plug-in is affected. The “all-permissions” tag allow to access local resources (files, network etc.).

