Security Basics mailing list archives

Re: Ten least secure programs


From: Devdas Bhagat <devdas () dvb homelinux org>
Date: Tue, 1 Jul 2003 22:34:14 +0530

On 28/06/03 15:08 -0700, Chris Berry wrote:
I'm putting together a list of what seem to be the ten least secure computer 
items in use today with the idea of having a set of things to recommend 
1) Passwords. Use RSA/DSA keys instead.

AGAINST people using, probably to be posted on the IT room door with a note 
like "NO, you cannot use the following!!".  Here is what I have so far, I'm 
looking for additions and comments.  The list is in order from with the 
worst offender being number one.  These should be products whose inheirent 
design is flawed, not that are just difficult to secure.  I expect vigorous 
discussion. *putting on flame retardent garments*  Oh, and leave Operating 
systems out of this one.

1) Microsoft Outlook
2) Outlook Express.
3) internet Explorer.

2) Telnet
4) Telnetd (not telnet).

3) Sendmail
4) IIS Server
5) Wireless networking
Wireless networks without IPSec.

6) PHP
7) ?
Unaudited code, in any language.
r* (rsh, rcp, etc)

0) Unpatched anything*

Devdas Bhagat

---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: