Forums
New posts
Search forums
Members
Current visitors
Log in
Register
What's new
Search
Search
Search titles only
By:
New posts
Search forums
Menu
Log in
Register
Install the app
Install
Forums
Archive
Archive
ASP .Net
Site Traffic Reporting
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Reply to thread
Message
[QUOTE="Amedee Van Gasse, post: 465429"] Juan T. Llibre shared this with us in microsoft.public.dotnet.framework.aspnet: I'm not a security export, so I won't argue about you on that. You could be right or it could be your perception. It's my own impression that most security problems are in software written in some version of C. But then again, with C you can shoot yourself in the foot and then no one else can figure out what you did, and with Perl you separate the bullet from the gun with a hyperoptimized regexp, and then you transport it to your foot using an array of arrays of arrays. However, the program fails to run and you can't correct it since you don't understand what the heck it is you've written. ;-) Currently: no. Not yet. There have been times that a vulnerability remained infixed for weeks or months. I can look it up if you want, but so can you. Google is your friend. I totally agree with you. That is why you should read again: <quote> IIS has been demonstrated to be a security risk in many ***PREVIOUS*** versions and I don't want to be the booby who proves that the (current) version of IIS (6) (...) is a security risk, too. </quote> Please read this: [URL]http://www.eweek.com/article2/0%2C1759%2C1240915%2C00.asp[/URL] It is about IIS 5. With such a bad history, one should always be careful. I totally agree with you that IIS 6 is the most secure web server of all IIS versions. IIS 6 even has less security advisories than its largest competitor, Apache 1.3.x. But this tells you nothing about the severity of a problem. It could also mean that people are actually looking at the code and finding bugs, whereas the bugs in IIS are left to be exploited at a later date. It is also unknown how many security bugs each IIS update fixes since the public does not have access to the code. The number of security updates is a double-edged sword. Lets not forget that Apache is an open source project with many eyeballs on the code (I'm not saying that there aren't many MS Eyeballs on IIS's code). I would expect a large proportion of those vulnerabilities to have been discovered by looking through the code rather than by other nefarious means. However, for a third party to discover a vulnerability in IIS they would have to have done it blind - this is often orders of magnitute harder. Good for you! You should always use the tools that best fit the purpose. If you can do it better/faster in VB.NET or C#, please do! [/QUOTE]
Verification
Post reply
Forums
Archive
Archive
ASP .Net
Site Traffic Reporting
Top