And getting back to Myth number one, how about the point of Apache which is
2/3 of the servers being run, being far less vulnerable than Windows Server
2003?
I read the entire article and found that the one seriously flawed part
of their argument. The rest of it was mostly spot on (mostly).
Since IIS is included with Windows 2000, 2000 server, 2003, and XP
Professional, and since many HOME users install it without knowing,
there is a LARGE base of ignorant people running IIS.
I've seen many companies running IIS as their web server and have never
even patches the server, never run the BSA, never looked at permissions,
and the root cause is ignorant people managing the servers.
There are very large companies running IIS as their production web
servers for Plant control, for Public web sites, etc... When I worked
for a design company we did work for a LARGE company that based 40+
sites out of 150+ sites on IIS 5, and then moved to IIS 6 - not one of
their sites had ever been compromised and all were the publics interface
to the company and it's products (thousands of doctors, patients,
mothers, counselors, etc... per week used the sites).
If you remove the installs of IIS by ignorant users, and setup IIS with
someone on the same technical level as those installing Apache, you end
us with both being stable and secure and as prone to being hacked as the
other.
SQL Slammer was another issue of ignorant users installing SQL server
again - once the idiots exposed the SQL data or management ports the
game was over. I have never seen a valid reason to expose the SQL data
or management ports to the PUBLIC. Sure, through a VPN or IP:IP
restriction at he very least, but not just open ports to it. If the
servers had been secured the worm would have not done anything.
What it really comes down to is that ignorant users and wanna-be's
should not be installing services until AFTER they learn about security
of ANY OS / Service. All systems, even Apache, should be behind a
firewall and not just one of those cheap routers that provides NAT only.