Tech Alert Briefing for 10/2/2002
Top 20 List of Internet Security Vulnerabilities Released
The US General Services Administration (GSA), FBI's NIPC, and the SANS Institute today announced a new list of the top 20 Internet security vulnerabilities.
The release of a targeted list of the top network vulneribilities is intended to help network administrators prioritize their efforts to plug common security holes.Many auditors and security managers typically rely on vulnerability scanners to detect network vulnerabilities.Such tools often times report thousands of vulnerabilities across hundreds of machines, potentially overwhelming administrators from focusing and ensuring that all systems are protected against the most common attacks.
The Top Twenty list aims to provide a prioritized list of vulnerabilities that require immediate remediation. The list is sorted by service, because in many cases a single remedy -- disabling the service, upgrading to the most recent version, applying a cumulative patch -- can quickly solve dozens of specific software flaws which might show up on a scanner.The list also includes step-by-step instructions and pointers to additional information useful for correcting the security flaws.
The complete list of vulnerabilities may be found at: http://www.sans.org/top20/
As a service to our readers, we have included the complete list of vendors who provide tools and services for detecting the SANS top 20 vulnerabilities in BOL Vendor Connect, Security - Information Security / Technology category.
Previous Tech Alerts:
09/02/02Microsoft Warns SysAdmins To Immediately Patch Identity Spoofing Flaw
08/21/02Microsoft releases patch to fix "critical" vulnerability inWindows 2000 systems that allow unprivileged users to logonto them interactively
08/09/02 Is Confidential Bank Information Walking Out Your Door?
07/30/02 Microsoft Continues to Patch Flawed Software
07/23/02 CERT advisory on PHP
07/15/02 Outlook Users Employing PGP Encryption Program Vulnerable to Hacking
07/11/02 Researchers Report Serious Flaw in IE
06/27/02 Microsoft Releases Critical Patch for Windows Media Player
06/18/02 CERT Warns of Critical Vulnerabilty in Apache Web Server
06/12/02 Sports Fans Beware: World Cup Virus Bounces Around the Net
06/07/02 Dead Man Tell No Passwords
05/31/02 Microsoft Issues Critical Warning Regarding Exchange Server
05/22/02 Microsoft SQL Spida Worm Slows Network Traffic
05/15/02 Virus Hoax 'JDBGMGR.EXE' Spreading Rapidly Thoughout Net
04/25/02 Klez Worm Reels in Banks with its Bait
04/11/02 Ten New Vulnerabilities Discovered in Microsoft IIS Server
04/09/02 New Virus Hoax Circulating Around Net
03/22/02 MyLife.B Virus Makes Its Way Around the Net
03/21/02 Microsoft Updates Its Warning on Critical Windows Vulnerability
03/14/02 New Virus (W32/Fbound-C) Spreading Rapidly in the Wild
03/08/02 Unauthorized E-Mail Scam Attempts to Steer Unwitting Customers to Fraudulent Bank Web Site
03/06/02 Klez-E Worm and W32.Gibe Virus Warnings
03/01/02 CERT Issues Warning on PHP Scripting Language Flaw
02/27/02 CERT Issues Warning on Internet Explorer and Outlook Flaw
02/22/02 SNMP Patches and Detection Tools Available
02/20/02 Email Address Belonging to Legitimate Security Site Hijacked to Deliver Dangerous Yarner Worm
02/15/02 Mass Mailing Email Worm Compromises Word 2000 Security Settings
02/13/02 SNMP VULNERABILITY
02/07/02 Bloodhound Mass Mailing Worm and Managing Risks in Wireless Networks
02/04/02 Microsoft Issues Collection of Security Fixes for Windows 2000
01/31/02 Copycat Virus Unleashed
01/30/02 Netscape Browser Vulnerable to Cookie Theft
01/28/02 "My Party" Mass Mailing Worm
01/18/02 IT Contingency Planning Guide, Information Security Checklist and Solaris Vulnerability
01/15/02 Trojan.StartPage Alters Web Browsers
01/12/02 New Internet Worm Gigger Masquerades as Microsoft Outlook Upgrade
01/08/02 Microsoft Universal Plug and Play Vulnerability
12/20/01 Holiday Themed Computer Virus Unleashed