The Web's 20 Worst Security Flaws
XsynackX writes "The SANS Institute released its Top-20 list of the biggest vulnerabilities on the web today. The SANS Top 20 Internet Security Vulnerabilities list is actually a compilation of two lists--the top 10 Windows vulnerabilities and the top 10 Unix vulnerabilities. The list goes into almost more detail than any one person could ever take in on individual security flaws, but provides a wealth of knowledge for those who like to get in-depth. Interestingly enough, the browser section of the Windows vulnerabilities lists everyone's favorite browser Internet Explorer with 15 flaws and Mozilla with only 7."
These flaws cover more then just "the web".
They include things like week passwords and non-web network threats.
---- join dshield.org Distributed Intrusion Detec
Fortunately for now, security through obscurity prevails for Firefox, since most exploits will likely target IE users. However, Firefox's development model is inherently better than IE's with regards to security, since the status of these vulnerabilities is known to all and they are fixed much more quickly. Why Microsoft is still in the browser game with their lame, few-and-far-between updates is beyond me.
...Internet Explorer with 15 flaws and Mozilla with only 7
Err... at this point, does it really matter? It's useful to compare BIND against djbdns (many security flaws vs. none), or Linux against OpenBSD (many security flaws vs. one remote hole in 8 years), but 15 flaws vs. 7 flaws? To me, that just says that both browsers are horribly insecure, and slightly more effort has been put into finding flaws in MSIE.
Tarsnap: Online backups for the truly paranoid
...seems to feel that posting a link to it on slashdot is a vunerability.
How many computers are too many?
Doesn't everyone that reads /. know that MS IE is a gaping security vulnerability by now. Do we *really* need to keep harping on it like a bunch of smug self-righteous motherfuckers?
I've always said that spyware was caused due to Internet Explorer being so popular.... If firefox keeps the rate of growth its doing I don't think it will be that long into we see spy/malware targeting Firefox as well....
Loading Please Wait....
Interestingly enough, the browser section of the Windows vulnerabilities lists everyone's favorite browser Internet Explorer with 15 flaws and Mozilla with only 7.
Don't think I'm trolling but this is like saying the USA has 27,000 nuclear weapons whereas Russia has only 13,000.
Banu
Top Vulnerabilities to UNIX Systems
1. A fool with root access.
If not ...
The article separately lists the top 10 Windows and top 10 Unix vulnerabilities. In this case, Top 10 plus Top 10 does not necessarily equal Top 20.
Sort of like if you considered the Top 10 fastest race cars at a Nascar race and the Top 10 fastest race cars at a soapbox derby race - the resulting list wouldn't be the Top 20 fastest race cars.
...everyone's favorite browser Internet Explorer with 15 flaws and Mozilla with only 7.
I don't think security flaws in something as commonly used as a web browser should ever be noted as "only" a certain number. Sure Mozilla beat IE, but the point still remains that it had 7 too many. I'll have to read this list when I get a chance and see how many of those were really windows issues and mozilla just passed the data on.
(And yes I know you'll never have bug free software)
can't sleep slashdot will eat me