Security Basics mailing list archives

Re: [OCLUG] Ten least secure programs


From: "Meritt James" <meritt_james () bah com>
Date: Tue, 01 Jul 2003 09:31:35 -0400

You forgot the SANS top ten list regularily put out.  It specifies
software and the specific vulnerabilities within them, both NT & Unix,
not to mention the list is regularily updated.

Jim

Andre Hall wrote:

You forgot Microsoft's ActiveX, Word and Excel - vulnerable

On Sat, 28 Jun 2003 15:08:38 -0700, Chris Berry wrote
I'm putting together a list of what seem to be the ten least secure
computer items in use today with the idea of having a set of things
to recommend AGAINST people using, probably to be posted on the IT
room door with a note like "NO, you cannot use the following!!".
 Here is what I have so far, I'm looking for additions and comments.
 The list is in order from with the worst offender being number one.
 These should be products whose inheirent design is flawed, not that
are just difficult to secure.  I expect vigorous discussion.
*putting on flame retardent garments*  Oh, and leave Operating
systems out of this one.

1) Microsoft Outlook
2) Telnet
3) Sendmail
4) IIS Server
5) Wireless networking
6) PHP
7) ?
8) ?
9) ?
10) ?

Chris Berry
compjma () hotmail com
Systems Administrator
JM Associates

"Within every man beats a heart of darkness." --The Shadow

_________________________________________________________________
Help STOP SPAM with the new MSN 8 and get 2 months FREE*
http://join.msn.com/?page=features/junkmail

--
Orange County Linux Users Group   http://www.oclug.org
To unsubscribe mailto:majordomo () oclug org?body=unsubscribe%20oclug

---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.

Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.

Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------

-- 
James W. Meritt CISSP, CISA
Booz | Allen | Hamilton
phone: (410) 684-6566

---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: