Advertisement
Promo

Industry watch Toolkit

FBI names 20 most-wanted security flaws

Robert Lemos, ZDNet.com ZDNet US

Published: 03 Oct 2001 08:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Systems Administration, Networking and Security (SANS) Institute unveiled a list of 20 software flaws this week that the group, along with the FBI, recommends be given special attention by corporate data managers.

The list includes seven security problems that affect all systems, six vulnerabilities specific to Microsoft servers, and seven flaws that affect various flavors of Unix, including Linux and Solaris.

"The idea is that this list is going to heighten awareness of the top threats," said Greg Shipley, vice president of consulting for network protection company Neohapsis. "If you take the stance of an in-the-trenches security practitioner, this definitely helps."

Along with many esoteric vulnerabilities -- such as the ISAPI flaw that allowed Code Red to spread -- the list also includes many common-sense steps that system administrators can take to secure their networks. For example, the list highlights the fact that most default installations of software are not secure, that many organizations do not perform regular backups and that weak or no passwords are frequently used.

The list builds on a Top 10 list that SANS released in June 2000. All but one of the original 10 flaws remain on the list.

That may indicate that many people are not listening to the message, said Shipley, but that doesn't negate the usefulness of the list.

"If the community did rally around this, the Internet would still be a lot safer," he said.

Sixteen months ago, vulnerabilities in the domain-name service software package BIND topped the list, followed by flaws in the Common Gateway Interface scripts commonly used by many Web sites to add interactivity.

The current Top 20 list doesn't rank the flaws, but does break them into general, Windows and Unix categories.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
31 out of 78 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

NoThomas NoThomas

Sure I can

Saturday 26 December 2009, 2:01 AM

11 comments
NoThomas NoThomas

It does not need clarification...

Saturday 26 December 2009, 1:30 AM

10 comments
ator1940 ator1940

Microsoft Loses Patent Case Appeal

Friday 25 December 2009, 9:35 PM

5 comments
Video icon

Video


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters