Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

The case for proper information or WHY CAN’T I UPGRADE THIS?

Posted on March 9, 2018 By Michael Kavka No Comments on The case for proper information or WHY CAN’T I UPGRADE THIS?

Legacy OSes, Legacy systems. We all know that it sucks having them. We all have to deal with them. Software companies do not always account for them though.

When you work internally in a medium to large business change happens slowly at times. I recently ran into a weird issue due to slow change. I went to update my CarbonBlack Response server in the mindset of security and fixing a few annoying bugs. I have done these updates without issue in the past. So when I got an OpenJDK dependency error I was rather taken aback. I tried to update OpenJDK, no go. The repos this version of Linux is using had no update to openJDK (1.8.0.r92 is what I needed). I decided to get CB support involved. We eventually set up a Webex so they could see directly what was going on, since none of the fixes they had sent me worked.

Turns out that it was not documented that the Linux version we were on will not get that version of OpenJDK, or anything newer available for it. Mind you the Linux version is a number of years old, but still supported by said Linux vendor. Nor is there a way around the issue with the upgrade process, so CarbonBlack basically cannot be updated unless I can get the proper change order pushed through to upgrade the Linux version. We tried everything, manually installing new versions of OpenJDK which succeeded but still was not being seen when the dependency check was being done.

The support person from CarbonBlack was going to let the devs there know about this and try to get documentation updated so others who might be looking to upgrade know they cannot with this version of Linux. The other thing that got me thinking was why is a security company like CarbonBlack relying on Java (OpenJDK) since it is so insecure? I like CarbonBlack’s products but this is a huge WTF in my book.

Rants, Security, Software Tags:Carbon Black, CarbonBlack, Java, OpenJDK, Upgrade

Post navigation

Previous Post: Random Thoughts Again
Next Post: What is Threat Hunting?

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Claude Fable Solves a Historical Cipher September 9, 2026 Bruce Schneier
  • Fort Scott restores systems after ransomware attack September 9, 2026 Joseph Topping
  • A “proof” of Fermat’s Last Theorem that fits the margin September 9, 2026
  • Over 36,000 exposed Plex servers vulnerable to recent flaws September 9, 2026 Sergiu Gatlan
  • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure September 9, 2026 Rem Dudas
  • Man gets 15 years for extorting women with AI-generated porn videos September 9, 2026 Sergiu Gatlan
  • New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access September 9, 2026 Sergiu Gatlan
  • 📢 Disable Windows Defender via Antivirus Fake Registration 🎙️ Threat actor… September 9, 2026
  • Google warns of new Chrome zero-day bug exploited in attacks September 9, 2026 Sergiu Gatlan
  • Cisco IOS XR Software Security Hardening Release: September 2026 September 9, 2026
  • ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th) September 9, 2026
  • Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults September 9, 2026 Mayank Parmar

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Claude Fable Solves a Historical Cipher September 9, 2026 Bruce Schneier
  • Fort Scott restores systems after ransomware attack September 9, 2026 Joseph Topping
  • A “proof” of Fermat’s Last Theorem that fits the margin September 9, 2026
  • Over 36,000 exposed Plex servers vulnerable to recent flaws September 9, 2026 Sergiu Gatlan
  • Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure September 9, 2026 Rem Dudas
  • Man gets 15 years for extorting women with AI-generated porn videos September 9, 2026 Sergiu Gatlan
  • New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access September 9, 2026 Sergiu Gatlan
  • 📢 Disable Windows Defender via Antivirus Fake Registration 🎙️ Threat actor… September 9, 2026
  • Google warns of new Chrome zero-day bug exploited in attacks September 9, 2026 Sergiu Gatlan
  • Cisco IOS XR Software Security Hardening Release: September 2026 September 9, 2026
  • ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th) September 9, 2026
  • Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults September 9, 2026 Mayank Parmar
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.