SANS released its annual Top 20 list of Internet security vulnerabilities. According to SANS the list compiled by consensus of contributors from "government agencies in the UK, US, and Singapore; the leading security software vendors and consulting firms; the top university-based security programs; many other user organizations; and the SANS Institute. "
For Windows, the SANS list suggests that the most vulnerable areas are Web servers & Web services, the Workstation service, RAS, Microsoft SQL Server, Windows authentication, Web browsers, file sharing applications, LSAS exposures, mail clients, and instant messaging. Not much has changed, eh?
The top 20 vulnerabilities for Unix and Linux platforms are BIND DNS, Web servers, authentication, version control systems, mail transport services, SNMP, Open Secure Sockets Layer (SSL), misconfiguration of NIS/NFS, databases, and the kernel itself.
You can learn about the specifics of these areas of vulnerability by reading the Top 20 list at the SANS Web site.
End of Article
You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor?
Register now
Free CDs Offer Fundamental Content for IT Pros Are you up to speed on the latest technologies and solutions? Don't miss out on your chance to get up to speed quickly on fundamental, in-depth information on some of the hottest topics in our library of content.
Let Your Users Reset Their Own Passwords: Free Download Try a 30 day free trial of Desktop Authority Password Self-Service – it provides an easy-to-use, robust system for allowing users to reset their own forgotten passwords or locked accounts.
Get Windows IT Pro & Mark Minasi’s Favorite Power Tools Guide Order Windows IT Pro now and get "More of Mark Minasi's Favorite Power Tools"--a in-depth guide to the most useful Windows commands --FREE with your paid order! Subscribe today, and save 58% off the cover price!
Deep Dive into VMware vSphere, eLearning Series Join John Savill to explore the major functionality capabilities of the vSphere virtualization platform, including identification of the changes from ESX 3.5.