Re: Obligatory jibe at Windoze & IIS (was: Windows Disaster Time)



"JeffM" <jeffm_@xxxxxxxxx> wrote in message
news:1122057247.699163.90880@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> > Joel Kolstad
> >...it reflects the fact that IIS is free whereas Apache isn't
> Got that backwards.

Sorry, my bad.

> Remember Vulnerability Note VU#713878 ?
> http://www.google.com/search?&q=internet-explorer+june+2004+CERT
> It was even covered by the national corporate [1] news media.
> Some even pointed out **gasp** that it only affected *Microsoft
> Windows*.

Is that the one where Microsoft had security patches out roughly a month
before the attacks started showing up, but of course many systems were
vulnerable because the system administrators hadn't bothered to apply them?

I suppose I would give you that you have to be _much_ more diligent about
security when running a Windows system than a *NIX system, in much the same
way that someone with a really fancy car needs to be a lot more diligent about
security than someone driving a clunker. (Not to imply that Apache is a
clunker, just that it's not as attractive to criminals as IIS.)

---Joel


.



Relevant Pages

  • RE: IIS6 Security and other web servers
    ... Will you have to learn Apache or IIS? ... IIS6 Security and other web servers ... I was discussing yesterday with a friend about the quality of IIS6 from ...
    (Security-Basics)
  • RE: IIS6 Security and other web servers
    ... Apache and IIS are much the same security wise nowadays - it comes down to ... I would say it comes down to 3rd party modules - Being OpenSource Apache ... IIS6 Security and other web servers ...
    (Security-Basics)
  • Re: IIS vs. Apache Security
    ... > Anyone here have any good documentation on IIS vs. Apache Security? ... > project I am rolling out because apparently "we all know how unsecure IIS ... *nix servers for this year and last outnumber IIS / Windows servers. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Web Server behind ZoneAlarm?
    ... >> IIS, if properly managed, like Apache, is secure. ... We've done public IIS ... IIS was terrible in security purposes, and I bet "Lythos" is just lying. ... which seems to be as secure as needed. ...
    (comp.security.firewalls)
  • RE: NT/2000 vs Unix based Web Servers
    ... the choice of web server platform borders on religious hysteria. ... In the case of IIS vs. ... Apache, which is the most common comparison made, each one has a lot to ...
    (Security-Basics)

Loading