|
|
Log in / Subscribe / Register

The SANS top-20 list

SANS has posted a new version of its 20 most critical Internet security vulnerabilities list. As always, this list is a good starting point for those looking for potential security problems on their networks. Here are some highlights from the current version:

  • Five of the twenty items concern Windows and other Microsoft software.

  • There are ten vulnerabilities in "cross-platform applications" listed. Some of these (commercial DNS servers, for example) do not apply to most Linux systems. But others do, including anti-virus software (ClamAV in particular), PHP-based applications (several vulnerabilities), database managers, file-sharing applications, media players, and Mozilla-based browsers.

  • There are only two Unix-specific vulnerabilities, and one of those is a general item on Mac OS X. The other vulnerability is "configuration weaknesses," with an emphasis on SSH attacks.

Once upon a time, this list was evenly divided between Windows and Unix vulnerabilities. A casual reading of the current list suggests that things have shifted in favor of Unix-based systems. While it may be true that Unix-based systems are easier to keep secure on the net, there is still no reason to be overly complacent. A system compromised by way of a Firefox or PHP vulnerability is still compromised.


The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2005, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds