
A matter of national security or a just a handy tool for network admin?
By Jo Best
Published: 9 October 2003 14:59 BST
An international anti-hacking study exposing the most common vulnerabilities exploited by hackers has received unequivocal backing from the British government as part of its efforts to protect the country's critical national IT infrastructure.
The research, published by the SysAdmin, Audit, Network, Security (SANS) Institute in Washington, shows the 10 flaws most commonly exploited by hackers in Microsoft Windows and the 10 most commonly exploited in Unix operating systems.
The list is published annually and this year revealed that the most problematic area for Microsoft is its web server, the Internet Information Service (ISS) server, and for Unix the Berkeley Internet Name Domain (BIND) DNS software.
The institute, with the US Department of Homeland Security, the Canadian Office of Critical Infrastructure Protection and Emergency Preparedness (OCIPEP), as well as the UK government's National Infrastructure Security Co-ordination Centre, have produced advice on how to tackle the vulnerabilities. The results of the research can be found on the SANS Institute website.
A Home Office spokesman told silicon.com that the British wing of the anti-hack effort had been at the "forefront of development in the area, sharing expertise, knowledge and our experience in terms of what private companies and government departments have experienced".
He added that while the research would have trickle-down benefits for the average user, the research would be of most use to the high-level tech workers who are responsible for protecting the UK's national IT infrastructure from attack.
The US research body, however, views the research as a much more grass-roots enterprise, aimed at getting systems administrators to sort out their software issues. Allen Paller, director of research for the SANS Institute, said in a statement: "The [list] defines the set of network security vulnerabilities that are most commonly used by hackers to break into systems. They should be addressed by network administrators as quickly as possible."
Aside from the guidelines on how to correct the flaws, it seems that something more than confusion has come out of the research. As a result of the study, some areas in Microsoft IE and Outlook have been revised or added to.
Speaking in Washington, NISCC Director, Stephen Cummings said: "Our colleagues at the SANS Institute have been undertaking essential work and we have been pleased to add our own expertise. We have helped to produce descriptions and remedial advice…As a result of the work, a number of scanning tools are available for system and network administrators to use. There is no quick fix for beating vulnerabilities, but listing and highlighting those which are most exploited is a very good start."
We seek 2 new ASP.net VB.Net SQL Server Oracle Developer for a British institute based in Coventry. The MIS team predominantly look after the web ...
New opportunity created by team expansion for an experienced Infrastructure Manager to join the IT team of a leading British company in the ...
Additional experience with the following technologies would also assist in your application: Crystal Reports / Business Objects, Cisco Switches / ...
CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.
Staffing Service Coordinates Sales Activities, Utilizes Business Intelligence With...
Teachers Association Turns to Centralized Data Repository to Improve Member Service
Financial-Software Leader Credits Productivity Boost, Reduced IT Costs to 2007 Software
United States Coast Guard Explores Potential to Enhance Training With Digital Note-Taking...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... XP lives, the femtocell 'truth', BlackBerry bashing… Reader Comments of the Week
Martin Brampton The Brampton Factor: Open source 'brotherhood' closed to co-operation Where's the real sharing?