Vulnerability Development mailing list archives

Re: Notes Domino Server Platform for e-commerce?


From: marc () MUCOM CO IL (Marc Esipovich)
Date: Wed, 9 Feb 2000 14:04:37 -0200


To date I have seen 0 issues with password problems and Notes/Domino.

Does it mean that there are 0 (zero) issues? I'm not so sure.
Was that Domino server ever audited?, are there overflows hidden deep
within? I'm sure there are.

What you're saying is, you're just running Domino, sitting and waiting for
someone to come up with exploits for it, way to go.

Can you trust a software which you don't have sources to? absolutely not.

The
Notes password is stored in an ID file.  For Inet use, the password is
like I said, stored within a database which is encrypted in a field. (64bit
International/128bit North American).

What kind of algorithm are we talking about here, size doesn't *awalys*
matter ;)

If you want a more robust web server, try WebSphere.  IBM's HTTPD.  A
great 'E-Commerce' webserver with tons going for it.  Check it out.

No, if you want a more robust webserver, try apache, I'm *positive* it was
audited far more than any webserver on the planet, WebSphere included.

Doesn't apache have *tons* going for it too? think about it.

If you absolutely *must* have a commercial webserver (I see no reason),
try Stronghold from C2Net.

        Marc Esipovich.

---
root is only a few clicks away...



Current thread: