This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

20 Most Critical Internet Security Vulns ~ Experts Consensus

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.sans.org/top20/
Version 6.0 November 22, 2005
"This SANS Top-20 2005 is a marked deviation from the previous Top-20 lists. In addition to Windows and UNIX categories, we have also included Cross-Platform Applications and Networking Products. The change reflects the dynamic nature of the evolving threat landscape. Unlike the previous Top-20 lists, this list is not "cumulative" in nature. We have only listed critical vulnerabilities from the past year and a half or so..
It includes step-by-step instructions and pointers to additional information useful for correcting the security flaws. We will update the list and the instructions as more critical threats and more current or convenient methods of protection are identified, and we welcome your input along the way…"

:ph34r: ;)
FYI…

- http://www.informationweek.com/shared/prin…cleID=174401665
Nov. 28, 2005
"… While most hacking between 1999 and 2004 targeted operating systems and Internet services on Web servers and E-mail servers, that changed this past year. Now, applications and network devices' operating systems have become the primary targets. For businesses, solving that problem is much tougher than just keeping up to date on Microsoft patches. Many of the new targets don't have systems for automated patches, and companies may not have the same processes and relationships with vendors to fix problems swiftly. And since the goal of these attacks isn't to spread mass infection like an "I Love You" worm, and instead is to steal information and money, they can go unnoticed… The applications under fire span the range of software programs a business might use and run on a variety of operating systems. They include enterprise backup software, the PHP scripting language, databases, peer-to-peer file sharing, Domain Name System server software, media players, instant-messaging applications, and Internet browsers. Even antivirus software makes the list, with vulnerabilities in security software from CA, ClamAV, F-Secure, McAfee, Sophos, Symantec, and Trend Micro, among others, raising the possibility of attackers taking over users' systems by using the software that's intended to protect them.
The second major finding of the report is that vulnerabilities in network operating systems, including Cisco's Internetwork Operating System, which SANS says runs some 85% of the routers and switches on the Internet backbone, represent a significant threat. Cisco acknowledged weaknesses in its operating system earlier this year, when it issued a security advisory for a serious IOS "heap-overflow" vulnerability that could let hackers get control of routers and switches running certain versions of the software… Targeted attacks don't typically get reported, unless there's a breach of customer data covered under disclosure laws such as California's. Tight-lipped companies hope to avoid bad publicity and prevent scaring more online consumers, under the theory that what they don't know won't deter them. But silence also makes it harder for security professionals to make the case for increased investment in security…"

:(