Advertisement
Promo

Security management Toolkit

The FBI's top 10 online security threats

John McCormick

Published: 28 Jan 2004 14:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

    Simple Network Management Protocol (SNMP)
    This one is pretty obvious. SNMP is used to remotely manage everything from printers to wireless access points and is therefore a major threat if not maintained properly. If you don't need or use SNMP then the fix is simple -- disable it. I suspect that a large number of the SNMP exploits are due to installations where the people running the system don't even realise it's there.

Risk level -- Critical
The vulnerabilities listed here are ones that hackers are most actively exploiting against Windows networks.

Fix
Patch or apply a workaround where appropriate. Some of these threats keep popping up as new vulnerabilities or ways to exploit them appear, but patches or workarounds are available for all the older exploits that are not being applied on many systems.

Some threats, such as the continuing problem with P2P file sharing, simply shouldn't be permitted on a business network. To block it, administrators must periodically scan for the presence of P2P and push upper management for the creation of strict enforcement of rules forbidding users from installing such software.

Final word
I suspect that some administrators are secretly happy that the SANS/FBI top 20 list isn't more widely publicised in the general media. If upper management questioned many IT departments about whether their company was covered against these threats, many of them would not get a very satisfactory response.

There are good reasons why some of these vulnerabilities (for example, popular software such as IIS and SQL Server) are perennial favourites. But some of the others should be eliminated in any properly managed operation. This is especially true for installations where unused services are allowed to remain active when they shouldn't even be there. Because they are rarely used, they also tend to be ignored when it comes to proper maintenance, which makes them doubly vulnerable and dangerous.

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
192 out of 393 people found this useful


Full Talkback thread

1 comment

  1. Any special reason why this is news today and not... Zapp Brannigan

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a Teufel Cinebar 50 system

Win a Teufel Cinebar 50 system

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters