SANS Top 20

Marco Ramilli
Date
4 December 2007
Read
Share

Every year SANSpublics the top twenty vulnerability of the year classified in different categories.This year:

Client-side Vulnerabilities in:
C1. Web Browsers
C2. Office Software
C3. Email Clients
C4. Media Players

Server-side Vulnerabilities in:
S1. Web Applications
S2. Windows Services
S3. Unix and Mac OS Services
S4. Backup Software
S5. Anti-virus Software
S6. Management Servers
S7. Database Software

Security Policy and Personnel:
H1. Excessive User Rights and Unauthorized Devices
H2. Phishing/Spear Phishing
H3. Unencrypted Laptops and Removable Media

Application Abuse:
A1. Instant Messaging
A2. Peer-to-Peer Programs

Network Devices:
N1. VoIP Servers and Phones
Zero Day Attacks:
Z1. Zero Day Attacks

In my opinion nothing happened; It's from many years that security land scape doesn't change. Client side vulnerabilities are more often browser vulnerability because browser like FireFox and IE are the most used client. On the other hand Web Application are growing up and not every developer is careful on security issues, so it's reasonable that it's still in the first Server Side Vulnerabilities. But..., actually I don't agree with the position of H1 and H2. My personal experience focused on security says that Phishing it's one of most important security problem of the current era. Preventing phishing means prevent security technical aspects and Social Security aspects; for the first lots of groups are working on with great results but for Social Security aspects the evangelist community is back yet. For this reason Phishing is one of the most important and used attacks. H1, is 'f course a really important problem but more fought during past security history; I believe that bounds of steps have been already done on this particular way, and for this reason not comparable with more recent phishing.

Marco Ramilli
Date
4 December 2007
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier