Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
XP And VFP6?
Message
From
11/10/2001 17:04:51
 
 
To
11/10/2001 01:37:07
General information
Forum:
Visual FoxPro
Category:
Other
Title:
Miscellaneous
Thread ID:
00565426
Message ID:
00567244
Views:
9
>And to think I'm usually the one defending MS's practices. But not in this case. It most certainly appears they need to get some more security experts assigned to the MS campus.

The issue is not so much a technical one as a policy one. The problem with IIS is not that it has more holes, but it exposes more functionality by default, which _exposes_ more holes. None of these worms would be a problem if the default IIS install was a bare bones, HTML only install, and all additional IIS functionality had to be intentionally added.

Apache is so much more secure because when you install it, all you get is a basic request parser to serve up pages on disk. IIS gives you bells and whistled out the wazoo, and the majority of the holes in the product (like the ones exploited by nimda and Code Red) are in those bells and whistles.
Erik Moore
Clientelligence
Previous
Next
Reply
Map
View

Click here to load this message in the networking platform