Re: 2003 Web Server Security flaw

From: Robert Waite (bob2dev_at_tampabay.rr.com)
Date: 12/30/03


Date: Mon, 29 Dec 2003 19:16:00 -0500

Thanks again.
Robert Waite

"Robert Moir" <bofh@mvps.org> wrote in message
news:u6T4%23sjzDHA.1740@TK2MSFTNGP12.phx.gbl...
> Robert Waite wrote:
> > Too bad it took so much work to get a direct & simple answer to a
> > simple question;
> > but, in my 20 years experience with user groups since Compuserve,
> > such is par for the course.
>
> Well I was somewhat cranky yesterday, and that didn't help. Sorry about
> that. Thing is, I honestly didn't see it as a simple question. Not that
many
> things in security are in my opinion.
>
> > So, if you two are right, in the next two years, we will hear on no
> > Win2003 Web Server sites
> > being compromised because of flaws, buffer over-runs, etc in those
> > three programs. Right?
>
> If we're right includes the code not being ran... and given that condition
> I'd reckon I was fairly safe.
>
> Of course as I also said, in an ideal world we should have more control
over
> what is included in the system install in the first place; while I'm
> obviously confident about what I said, the stakes are rather too high if
I'm
> wrong.
>
> Regards
> Rob Moir.
>
>