Security Basics mailing list archives

Re: Betr.: upgrading to IE6 on w2k servers


From: "Philip Wagenaar" <p.wagenaar () accon nl>
Date: Mon, 02 Aug 2004 09:14:43 +0200

Why is IIS 6 (not 3,4,5) so much less secure then IIS?

Maybe Microsoft should change the name of their products more often, because IIS 6 is a totally other product then IIS5.

Met vriendelijke groet,

Philip Wagenaar
Junior Projectleider ICT

AccoN Accountants & Adviseurs
ICT Project Bureau
Postbus 5090
6802 EB Arnhem
The Netherlands

tel. +31 (0)26-3842384
fax. +31 (0)26-3630222
mobile: +31 (0)6-25388935
MSN/E-mail: p.wagenaar () accon nl
Yahoo: philip_wagenaar
http://www.accon.nl


Mircea MITU <mmitu () bitdefender com> 30-07-04 23:14 >>>
On Wed, 2004-07-28 at 09:18 +0200, Philip Wagenaar wrote:
My reasons for switching to iis are new security model, secure by default, 

You must be kidding.
If you're looking for "secure by default" you should look at chroot-ed
Apache from OpenBSD or thttpd or RedHat' Stronghold or AOLServer. Or
even plain Apache. At least you could search http server and you'll find
a dozen of http servers more secure than iis.

Beside that he was talking about IE, not IIS.
Anyway, you made my day with this joke ;)



-- 
This message was scanned for spam and viruses by BitDefender
For more information please visit http://linux.bitdefender.com/ 



##################################################################

Dit e-mailbericht is uitsluitend bestemd voor de geadresseerde.
De informatie hierin is vertrouwelijk, zodat het derden niet is
toegestaan om daarvan kennis te nemen of dit te verstrekken aan
andere derden. Indien u dit e-mail bericht ontvangt terwijl het
niet voor u bestemd is, verzoeken wij u contact op te nemen met
de afzender en de informatie te verwijderen van iedere computer.
Bij voorbaat dank. 

==================================================================

The information transmitted in this e-mail is intended only for
the person or entity to which it is addressed and contains
confidential information. Any review, retransmission or other
use by persons or entities other than the intended recipient is
prohibited. If you received this in error, please contact the
sender and delete the material from any computer. Thank you. 

##################################################################

#####################################################################################
This e-mail message has been scanned for Viruses and Content and cleared 
by MailMarshal
#####################################################################################

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: