The most over- and under-rated vulnerabilities
So what are the overrated vulnerabilities? A few selections from the list include:
- PGP vulnerabilities. As the authors assert, there is no known
case of somebody having actually broken PGP's encryption.
- SNMP; "
As long as the default community strings have been changed, SNMP should be fairly safe. Actual exploitation using SNMP has been rare.
" - Cross-site scripting. Actual cross-site scripting exploits
are rare; there is usually a more direct route to what the crackers
want.
- Gopher vulnerabilities. Evidently some people are still concerned about Gopher holes.
So, rather than running out to patch that Gopher server, what should you really be worried about? The list includes:
- Remote procedure call vulnerabilities. RPC remains dangerous,
and certainly should not be exposed to the internet.
- Wireless networks which are easy to find and penetrate, and
which often live inside firewalls.
- Keystroke loggers and spyware.
- WebDAV servers. This one makes the list mostly due to the potential of compromising the web server, and (on Windows, at least) thus the whole machine.
Interestingly, virus-susceptible email systems do not make the list,
despite the fact that this type of vulnerability has probably created more
in the way of security costs - especially recently - than any other.
Clearly this vulnerability is underrated, given that it remains unclosed
after all these years. Risk, evidently, is still in the eye of
the beholder.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
