Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Reality of Perception
Tim Mullen, 2003-04-07

A new poll finds that seventy-seven percent of security professionals believe Microsoft products are insecure. But a closer look at the survey tells a far more interesting story.

Comments Mode:
The Reality of Perception 2003-04-07
Anonymous (6 replies)
The Reality of Perception 2003-04-07
Bill Hey <bill.hey@nospam.dsia.com>
The Reality of Perception 2003-04-07
Peter
I'm not certain I understand why Linux was brought up here (it doesn't appear in the parent article), but I doubt the poster has much historical experience on which to base this claim.

I've run Linux firewalls and servers for nearly a decade now, and the distribution of attacks has changed markedly over the past few years. If you looked at my firewall logs from, say, five years ago, you would have seen that most attacks targeted services like FTP, telnet, rsh, DNS, and the like, nearly all of which at that time were provided by *nix servers.

A quick glance over one of last week's logs from a client's firewalls shows a very different picture. Most attackers now target the netbios ports, MS SQL, and MS directory services. Sure I still get a few probes for broken FTP and DNS servers, as well as for proxies like Squid or Socks, but they are *much* fewer in number than the probes for vulnerabilities in Microsoft products.

Of course, as the poster argues, the relative market shares of MS and *nix servers plays a role here, but I also believe that Internet server software for *nix machines is much more "battle-tested" than equivalent MS software for two reasons.

One is simply that, for most services, *nix software, e.g., wu-ftpd, has been around a lot longer than the equivalent MS products. Second, and nearly as important in my view, is that the source code for most common *nix applications is freely available. While I don't subscribe to the theory that all open-source products are, per se, more secure, I do believe this argument applies to the best-known and most widely-used products (compare, e.g., Apache and IIS, or PostgreSQL and MS SQL-Server).



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/152/19199#19199
The Reality of Perception 2003-04-08
R Mortimer
It's not just market share 2003-04-08
Anonymous
Re: AnonymousPeon 2003-04-08
Just a point
Sorry, that's crap 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-07
AnonymousPeon (2 replies)
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception - heh 2003-04-07
Anonymous (1 replies)
The Reality of Perception - 2003-04-08
AnonymousPeon (1 replies)
The Reality of Perception - 2003-04-09
Anonymous (1 replies)
The Reality of Perception 2003-04-07
ralf
The Reality of Perception 2003-04-07
Bill Hey <bill.hey@nospam.dsia.com> (1 replies)
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
anonybori
The Reality of Perception 2003-04-07
Scott Sorrentino (1 replies)
Stupid unstable patches 2003-04-08
Anonymous
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception 2003-04-07
Penguinisto (1 replies)
The Reality of Perception 2003-04-08
Anonymous
The reality of your techs 2003-04-07
Andy Wood
The Reality of Perception 2003-04-07
Anonymous (2 replies)
The Reality of Perception 2003-04-08
Anonymous
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
Anonymous
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
Gary Fisher
The Reality of Perception 2003-04-08
Anonymous
My look on things 2003-04-08
DC0 (1 replies)
My look on things 2003-04-10
Anonymous
It's easy Tim - listen up! 2003-04-08
Anonymous
The Reality of Perception 2003-04-08
Wisconsin (1 replies)
The Reality of Perception 2003-04-10
blacklight
dont blame MS-blame these stupid poeple 2003-04-10
ab_s0248@yahoo.com
The Reality of Perception 2003-04-10
Anonymous
Patch Management 2003-04-11
mesmer
The Reality of Perception 2003-04-11
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus