OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Alderson, John (John.AldersonFMR.COM)
Date: Thu Oct 04 2001 - 12:04:20 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    > -----Original Message-----
    > From: Derek D. Martin [mailto:ddmmclinux.com]
    > Sent: Thursday, October 04, 2001 8:49 AM
    > To: Kevin Kaminski
    > Cc: 'focus-mssecurityfocus.com'
    > Subject: Re: ICMP, NT and IIS: What is a safe cocktail?
    >
    >
    > -----BEGIN PGP SIGNED MESSAGE-----
    > Hash: SHA1
    >
    > Kevin Kaminski said:
    >
    > > I am looking at deploying a Win2K IIS server on the
    > Internet. The only
    > > services offered are IIS on port 80 and IPSec for
    > administration. While
    >
    > Don't do it! You must resist!
    >
    > Seriously... even the Gartner Group, not renowned for being
    > fans of open
    > source software, are advising people not to use IIS, and to
    > investigate alternatives.
    >
    > http://www3.gartner.com/DisplayDocument?doc_cd=101034
    >

    Gartner isn't renowned for technical accuracy either. This article only
    highlights ill-informed opinion. The fact is that a properly configured IIS
    box is quite tight. If anyone is expecting to do a default install and pop
    anything on the wire and be safe, well...

    John Alderson