SANS Top 20 Vulnerabilities

SANS released its annual Top 20 list of Internet security vulnerabilities. The list is a good checklist of applications and services you might considering double-checking to ensure proper security.

ITPro Today

October 11, 2004

1 Min Read
ITPro Today logo

SANS released its annual Top 20 list of Internet security vulnerabilities. According to SANS the list compiled by consensus of contributors from "government agencies in the UK, US, and Singapore; the leading security software vendors and consulting firms; the top university-based security programs; many other user organizations; and the SANS Institute. "

For Windows, the SANS list suggests that the most vulnerable areas are Web servers & Web services, the Workstation service, RAS, Microsoft SQL Server, Windows authentication, Web browsers, file sharing applications, LSAS exposures, mail clients, and instant messaging. Not much has changed, eh?

The top 20 vulnerabilities for Unix and Linux platforms are BIND DNS, Web servers, authentication,  version control systems, mail transport services, SNMP, Open Secure Sockets Layer (SSL), misconfiguration of NIS/NFS, databases, and the kernel itself.

You can learn about the specifics of these areas of vulnerability by reading the Top 20 list at the SANS Web site.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like