Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
Good idea or not? IIS Intranet server on machine running
Message
 
To
06/04/2012 16:46:43
Al Doman (Online)
M3 Enterprises Inc.
North Vancouver, British Columbia, Canada
General information
Forum:
Microsoft IIS Server
Category:
Other
Miscellaneous
Thread ID:
01540087
Message ID:
01540633
Views:
67
>>In fact the service record of IIS 7 for vulnerabilities has been much better than any of the *nix servers available.
>
>Interesting... do you have some stats to back that?

Here are a couple that I could dig up:

IIS 7:
http://secunia.com/advisories/product/17543/?task=statistics

Apache:
http://secunia.com/advisories/product/73/?task=statistics


Microsoft has been for years comparing attach vulnerabilities on non-MS studies and there really hasn't been any challenge to that. All the complaints you hear about IIS security goes back to pre-IIS6.

As we said before 99% of security breaches today don't actually go through the server's internals, but through application weaknesses which you can screw up in any development tool and language.

If you actually follow the server mfr. security guidelines for applicaiton security you are very secure (for any vendor). You might also not have much of an application to run becuase the requirements can be very strict.

In the end it's up to us as developers to make sure sites don't get hacked, not server vendors. This means we have to have at least a fundamental understanding of security at the OS level.

+++ Rick ---
+++ Rick ---

West Wind Technologies
Maui, Hawaii

west-wind.com/
West Wind Message Board
Rick's Web Log
Markdown Monster
---
Making waves on the Web

Where do you want to surf today?
Previous
Reply
Map
View

Click here to load this message in the networking platform