RE: WebServer?

From: McCammon, Keith (Keith.McCammon@eadvancemed.com)
Date: 02/13/02


Date: Wed, 13 Feb 2002 10:45:26 -0500
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: "CHM Security" <chmsecurity@hotmail.com>, <focus-ms@securityfocus.com>

I can already see where this thread is going to end up, but...

In my experience (and I'm sure that most would agree), the server
software has almost nothing to do with the security of the system.
Apache, out of the box, is generally considered to be more secure than
IIS (also OOTB), and this is largely due to the fact that Apache isn't
as closely tied to the operating system as IIS. However, either can be
compromised, and either can also be hardened considerably, and server as
a very stable, secure platform. Both of the recent IIS worms, for
example, were 100% preventable without a single patch.

As far as stats go, you're not going to find much hard data on "Apache
vs. IIS." Server exploits, by their very nature, are specific to
certain platforms, and cannot be held side-by-side for comparison.
Every try a SQL Server exploit on an Oracle system?

-----Original Message-----
From: CHM Security [mailto:chmsecurity@hotmail.com]
Sent: Tuesday, February 12, 2002 9:59 PM
To: focus-ms@securityfocus.com
Subject: WebServer?

Apache vs IIS 5 on Win2k server. Is there any documentation on actual
compromises of the systems to base which one is actually more secure?
I'm
sure out of the box Apache blows it away, but if configured properly is
it
still that much better than an IIS 5 box?

_________________________________________________________________
Join the world's largest e-mail service with MSN Hotmail.
http://www.hotmail.com



Relevant Pages

  • Re: Apache vs IIS
    ... Windows Server not on my Linux Server so there for I would chose IIS. ... Not that Apache is bad but ASP.NET is far easier and faster to create good web forms in. ... PHP on a IIS server is rather easy to run once you install PHP on a PC but if you only use PHP why not use Apache for Windows. ...
    (alt.php)
  • Re: Apache vs IIS
    ... Windows Server not on my Linux Server so there for I would chose ... Not that Apache is bad but ASP.NET is far easier and faster to ... IIS is designed for ASP, ... Apache running on a Linux server. ...
    (alt.php)
  • Re: Apache vs IIS
    ... my Windows Server not on my Linux Server so there for I would ... IIS is designed for ASP, ... can run asp on Apache, ... in running php from IIS vs Apache. ...
    (alt.php)
  • Re: Apache vs IIS
    ... my Windows Server not on my Linux Server so there for I would chose IIS. ... Not that Apache is bad but ASP.NET is far easier and faster to create good web forms in. ... IIS is designed for ASP, ... PHP on a IIS server is rather easy to run once you install PHP on a PC but if you only use PHP why not use Apache for Windows. ...
    (alt.php)
  • Re: Apache vs IIS
    ... on my Windows Server not on my Linux Server so there for I ... IIS is designed for ASP, ... you can run asp on Apache, ... PHP on a IIS server is rather easy to run once you install PHP on ...
    (alt.php)