2006 Operating System Vulnerability Summary

In this article, Matthew uses nmap and nessus against actual installs of various operating systems as part of his research. A variety of operating sytems were tested including Windows XP, Server 2003, Vista Ultimate, MacOS, FreeBSD, Solaris, Fedora Core, and Slackware. “As far as ‘straight-out-of-box’ conditions go, both Windows and OS X are ripe with remotely accessible vulnerabilities. Even before enabling the servers, Windows based machines contain numerous exploitable holes allowing attackers to not only access the system but also execute arbitrary code. Both OS X and Windows were susceptible to additional vulnerabilities after enabling the built-in services. Once patched, however, both companies support a product that is secure, at least from the outside. The UNIX and Linux variants present a much more robust exterior to the outside. Even when the pre-configured server binaries are enabled, each system generally maintained its integrity against remote attacks.”

17 Comments

  1. 2007-03-30 9:05 pm
  2. 2007-03-30 9:31 pm
  3. 2007-03-30 9:48 pm
    • 2007-03-31 4:29 am
      • 2007-03-31 6:13 pm
  4. 2007-03-30 10:08 pm
  5. 2007-03-30 11:18 pm
  6. 2007-03-30 11:26 pm
  7. 2007-03-31 8:45 am
    • 2007-03-31 8:35 pm
      • 2007-04-01 8:44 am
        • 2007-04-01 1:07 pm
  8. 2007-03-31 9:55 am
  9. 2007-04-01 11:26 am
    • 2007-04-01 9:57 pm
      • 2007-04-02 4:35 pm
  10. 2007-04-02 1:44 am