Re: "Secure" Web Hosting?

From: Gaspar de Elías (gaspar.delias_at_gmail.com)
Date: 11/29/04

  • Next message: David Gillett: "RE: DOS Attack?"
    Date: Sun, 28 Nov 2004 23:12:46 -0300
    To: "Germano, Tomas" <tgermano@metrovias.com.ar>
    
    

    Dear Mark:

    There is something that we shouldn't forget about: Linux is as secure
    as you want it to be, so i agree with Tomas Germano, i think we should
    use an OS that make us comfortable.
    If you feel comfortable using Linux,BSD, or windows or whatever use
    it, but it's not a good idea to learn while your server´s security is
    in risk.
    Windows has a lot of security flaws, but if you install all new
    patches you won't have mayor trouble. On linux you can have better
    control on your ports, applications, but you have to know how to deal
    with it.
    I would recommend you Mark to use Linux if you feel you can handle it.
    Actually i'm still learning linux, but it's great.

    Thanks for your time.
    Gaspar de Elias
    Cordoba, Argentina

    On Fri, 26 Nov 2004 09:52:32 -0300, Germano, Tomas
    <tgermano@metrovias.com.ar> wrote:
    > I think that you mount an Apache Web Server on a Windows 2000 or 2003 (I
    > don´t know if Apache work on W2003) and you secure the Operative Sistem, you
    > are fine or more secure that usind IIS.
    >
    > I don´t test IIS 6.0 over 2003
    >
    > Sorry for my English
    >
    > Tomas A Germano
    > Analista de Seguridad
    > Metrovias.
    > Argentina
    >
    > -----Mensaje original-----
    > De: Mark Spencer [mailto:mspencer@evidentdata.com]
    > Enviado el: Miércoles 24 de Noviembre de 2004 11:49
    > Para: security-basics@securityfocus.com
    > Asunto: "Secure" Web Hosting?
    >
    >
    >
    >
    > Hello all,
    >
    > I'm looking for suggestions on web hosting providers that pay particular
    > attention to security issues, e.g. hardening networks, servers, and
    > applications.
    >
    > On a somewhat related note, if I wanted to host a web server myself,
    > what is the recommended platform for getting a web server online in a
    > secure and intuitive fashion? I know that OpenBSD has an excellent
    > reputation, but may be difficult to setup for someone that hasn't spent
    > much time with BSD. What about EnGarde Linux?
    >
    > Thanks!
    >
    > Mark
    >
    >
    > El contenido de este mail y cualquier archivo adjunto son confidenciales.
    > Está dirigido solo a los destinatarios. Cualquier divulgación, distribución
    > o copia de esta comunicación o cualquiera de sus contenidos está prohibida.
    > Si Ud. ha recibido este mail por error por favor reenvíelo al remitente
    > inmediatamente, borre el original y cualquier copia que resida en su
    > computadora.
    >
    >

    -- 
    Gaspar de Elías
    

  • Next message: David Gillett: "RE: DOS Attack?"

    Relevant Pages

    • Re: Ten least secure programs
      ... Subject: Ten least secure programs ... only someone that's hard up to bash Linux users would assume this. ... > corrected virtually all current and yet to be discovered security issues ...
      (Security-Basics)
    • RE: Ten least secure programs
      ... contrary to the statistics. ... corrected virtually all current and yet to be discovered security issues ... with Linux. ... Subject: Ten least secure programs ...
      (Security-Basics)
    • RE: Religion... was RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
      ... there is no A/V software for Linux that protects ... Of course, many of them do run A/V software, but it's to protect Windows ... In today's environment, software *must* be secure first, with usability added ... Microsoft systems take the opposite approach, ...
      (Full-Disclosure)
    • Re: is that a good offer for a server installation?
      ... SO linux based upon kernel 2.6xx ... installation of cwfm (a software that manages files, at first I believed that should be created by them, but then I found out to be free on the net http://cwfm.sourceforge.net) upload and download are managed via http ... they told him that ftp is not secure for this and their program is based ... they use a https connection then it should be secure enough. ...
      (comp.infosystems.www.servers.unix)
    • Linux v Dedicated NAT routers - secure remote differences
      ... using NAT routers can get a secure ... remote tunnel from a Windoze machine behind it to talk through a Checkpoint ... I can't with a linux NAT box. ...
      (comp.security.firewalls)