New SANS/FBI Top 20 List
An anonymous reader submits "The SANS Institute (together with the FBI) published today an updated version of its list of
The Twenty Most Critical Internet Security Vulnerabilities.
As usual, part of the news is that not too much has changed. The list is split into 10 Unix and 10 Windows vulnerabilities. Leaders are BIND and IIS (last year it was RPC on the Unix side). But some issues (weak passwords) made it into both lists.
For last years version, see here. In addition to this list, and a lot of other stuff, the SANS institute is behind DShield and the Internet Storm Center."
Looks like the site is slashdotted... :)
oh wait...it's my 33.6 modem
No, it just means that a link from slashdot should be on the list as a potental site vulnerablility :-)
Since when has this country used intellectual elite as a pejorative term?
There aren't two internets running, one for Windows and one for Unix
Yes, there are. One is for IE, and one - for everything else.
(Yes, I am expecting flames to correct my narrow view of internet and tell me that there is more than just web browsing, blah,blah. But you see my point, don't you?)
Jobs? Which jobs?
I think they forgot to mention the /. effect as being one of the greatest threats on the net. It should rank up there towards #1 on both Windows & Unix.
Good security is based upon reality and common sense. Common sense is a function of having common knowledge.
only 59 comments on the story, and their server's hosed already. And these people are trying to tell us how to keep the net running smoothly?
Yeah, they sent me an email telling me to use a better password than "bitemefbi". And I haven't installed their new backdoor yet, either. Some people are never satisfied...