SANS/FBI Release Top 20 Security Vulnerabilities
theBraindonor writes "SANS Institute and the FBI have compiled a listing of the The Twenty Most Critical Internet Security Vulnerabilities. The list is broken down into two groups: Windows Systems and Unix Systems." The list of Unix vulnerabilities is also a list of the network programs I (and presumably many others) use most. It's a good thing there's BugTraq.
#8 is listed here.
If you are using IE, your computer is vunerable to numerous security breaches.
If this is installed on EVERY Windows computer by default, I believe that this should be rated higher than those vunerabilities in applications that are only installed by default on SOME Windows versions (IIS).
They left Outlook and it's derivatives off the Windows list. Nevermind the root VBS cause.
But they seem to have really had to reach to get 10 for Unix.
Man... how much did this 'study' cost?
when a vendor installs an application BY DEFAULT on EVERY single version they ship and it is considered at top 10 vundeability I would say that is more important (see previous comment here) than individual applications that are GENERALLY not installed by default on UNIX based OSs.
.02
Just my worthless
They forgot to list one of the most obvious ways of breaching computer security measures: social engineering.
If you can get the information that you want (eg passwords) from a person who knows the information, all the patches in the world won't protect your network...
--
http://www.aikiweb.com - AikiWeb Aikido Information
Plus, you don't even need to spend on AV software from snake oil vendors.
All that's needed is to make the 'Edit' command the default in the registry for all types of WSH-recognized extensions, such as .js and .wsh. Unfortunately the default is 'Open', which executes the script.
Once you do this you can simply sit there and watch the script worms hit - the only thing you'll see are instances of Notepad all over the place (with the code, to boot). Quite funny (in a sick sort of way).
the "Slashdot Effect" DOS did not make the top 20.
Never answer an anonymous letter. - Yogi Berra
Apache is optimized and was originally designed for Unix. FTP is a standard Internet protocol that likely had its origins in Unix. While the problems you state afflict Windows and Unix alike, they cannot be "traced to Windows." They should be under a generic category for all systems, as HTTP and FTP servers are, in general, large security risks, if caused by nothing more than improper setup.
The user. Windows OR Unix.
What's in a Sig?
have some fun with ipchains and the "mirror" directive. all of a sudden, to him, your machine will appear to be an exact duplicate of his. maybe he'll even root his own machine in the process :-P