Hmm, the link in the TechTV article is bad... it says 'annual top 20', but it links to #W4 so it ends up down the list at vulnerability #4 instead of the index. Very odd.
SANS is a pretty good group, and has taken a very non-OS centric attitude towards things. When I was at the SANS conference in 2001 Northcutt did joke about Windows a little bit, but he also stated that since it was everywhere the best way that we could serve would be to understand it and learn how to secure it. They also had some incredibly knowledgeable instructors.
Anyway, pay attention to the top-20 list, it's all good advice. Also check out the SANS reading room at http://rr.sans.org.
Also if you have the time, go through the GIAC certification process... it's pretty intense and you learn quite a bit.
|