November 24, 2003

CERT issues Quarterly Summary of Top Incidents and Vulnerabilities

CERT issued its quartly report today to draw attention to the types of attacks reported to their incident response team, as well as other noteworthy incident and vulnerability information. The summary includes pointers to sources of information for dealing with the problems.

No real suprises. Here is a quick recap for those with their heads in the sand for the last quarter:

  1. W32/Mimail Variants
  2. Buffer Overflow in Windows Workstation Service
  3. Multiple Vulnerabilities in Microsoft Windows and Exchange
  4. Multiple Vulnerabilities in SSL/TLS Implementations
  5. Exploitation of Internet Explorer Vulnerability
  6. W32/Swen.A Worm (Personal note: I HATE this one)
  7. Buffer Overflow in Sendmail
  8. Buffer Management Vulnerability in OpenSSH
  9. RPCSS Vulnerabilities in Microsoft Windows

Happy reading. Make a game of it... figure out how many of these impacted your office, and how much the associated costs were. Now imagine if you got 5% of that as a Christmas bonus. Sickening... isn't it?

Posted by SilverStr at November 24, 2003 05:05 PM | TrackBack
Comments

If I take the term "office" loosely and extend it to my client's offices/factories, that 5% is probably more then I make...

Posted by: Wim at November 24, 2003 09:10 PM

People use sendmail?

Also aren't 4 (SSL) and 8 (SSH) linked together?

Posted by: Arcterex at November 25, 2003 12:17 PM