News

The web server that actually holds the file sees it as a GIF file, and serves it accordingly, but when the "image ... isn't within Java itself, but results from weak web application security.
The attack is simply a mashup of a GIF picture and a JAR (Java applet ... Sun could restrict their Virtual Machine or web applications could continually check and filter these hybrid files ...