The SANS top-20 list
- Five of the twenty items concern Windows and other Microsoft
software.
- There are ten vulnerabilities in "cross-platform applications"
listed. Some of these (commercial DNS servers, for example) do not
apply to most Linux systems. But others do, including anti-virus
software (ClamAV in particular), PHP-based applications (several
vulnerabilities), database managers, file-sharing applications, media
players, and Mozilla-based browsers.
- There are only two Unix-specific vulnerabilities, and one of those is a general item on Mac OS X. The other vulnerability is "configuration weaknesses," with an emphasis on SSH attacks.
Once upon a time, this list was evenly divided between Windows and Unix
vulnerabilities. A casual reading of the current list suggests that things
have shifted in favor of Unix-based systems. While it may be true that
Unix-based systems are easier to keep secure on the net, there is still no
reason to be overly complacent. A system compromised by way of a Firefox
or PHP vulnerability is still compromised.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
