Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Search Engines Used to Push Traffic to Malware Sites | Main | Cyberwarfare Threatens Operational Capability »

SANS Updates Top 20 Vulnerabilities List

The latest update to the SANS Top 20 List includes the usual suspects of client application vulnerabilities, browser vulnerabilities, and poor policies and/or enforcement. The list seems to have something for everyone. While operating systems are less vulnerable to worms than in the past, desktop apps are being exploited more effectively. The ones that caught my eye at first were vulnerabilities in backup software, anti-virus applications, and databases.

Backups tend to run with elevated authorizations to read many directories making them a prime target of attack. I for one don't think about backups much except when I need them or there is a problem with the scheduled jobs that run them. This is one case where out of sight out of mind is a problem.

Anti-virus software is also on the list with a Who's Who list of top AV vendors having remote execution vulnerabilities in their software. Attacking AV is like a biological pathogen that attacks the immune system, they can open the doors to other pathogens/malware.

Databases are of course on the list. These systems store the "crown jewels" of a company, of course they'll be a target. A combination of vulnerabilities in listeners, which pick up requests from the network, default configurations and poor password policies/enforcement don't help to protect the valuables.

The lowest hanging fruit that we seem to keep missing is with basic configuration and password policies.


The default configurations for many operating systems and services continue to be weak and continue to include default passwords. As a result, many systems have been compromised via dictionary and brute-force password guessing attacks in 2007!

The full list is available at http://www.sans.org/top20/

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/541

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net