Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Reality of Perception
Tim Mullen, 2003-04-07

A new poll finds that seventy-seven percent of security professionals believe Microsoft products are insecure. But a closer look at the survey tells a far more interesting story.

Comments Mode:
The Reality of Perception 2003-04-07
Anonymous (6 replies)
The Reality of Perception 2003-04-07
Bill Hey <bill.hey@nospam.dsia.com>
The Reality of Perception 2003-04-07
Peter
The Reality of Perception 2003-04-08
R Mortimer
It's not just market share 2003-04-08
Anonymous
Re: AnonymousPeon 2003-04-08
Just a point
Sorry, that's crap 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-07
AnonymousPeon (2 replies)
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception - heh 2003-04-07
Anonymous (1 replies)
The Reality of Perception - 2003-04-08
AnonymousPeon (1 replies)
The Reality of Perception - 2003-04-09
Anonymous (1 replies)
The Reality of Perception 2003-04-07
ralf
The Reality of Perception 2003-04-07
Bill Hey <bill.hey@nospam.dsia.com> (1 replies)
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
anonybori
The Reality of Perception 2003-04-07
Scott Sorrentino (1 replies)
Stupid unstable patches 2003-04-08
Anonymous
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception 2003-04-07
Penguinisto (1 replies)
The Reality of Perception 2003-04-08
Anonymous
The reality of your techs 2003-04-07
Andy Wood
The Reality of Perception 2003-04-07
Anonymous (2 replies)
The Reality of Perception 2003-04-08
Anonymous
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
Anonymous
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
Gary Fisher
The Reality of Perception 2003-04-08
Anonymous
My look on things 2003-04-08
DC0 (1 replies)
My look on things 2003-04-10
Anonymous
It's easy Tim - listen up! 2003-04-08
Anonymous
Windows 2000 Server -- with 3 months of free MSN access ! 2003-04-08
Chris Caydes
Well, Mr. Mullen's columns are certainly those whose get the most comments posted... And that is why I like about them...

I would have to disagree with the above comment that stated that MS softwares cannot protect themselves against holes with anything else than a patch.
There are various security tools (shipped with Windows, in the ResKit, or by 3rd parties) that allow you to harden MS OSes and softwares.

Yet these tools are less popular than equivalent Unix tools (setuid, chroot, ACLs, tripwire, sudo, openssh, etc.). Even the Event Viewer in Windows is often not used as well as its Unix equivalent syslog.

To me a part of the problem is historical Windows culture : the apparent similarity of "Windows 2000 Server" and "Win 95 Home Edition with 3 months of free MSN access" make some believe that operating a critical server running on MS is easy.
Connecting from the system console with the administrative account is done exceptionnally in Unix, but it remains common in Windows, even for things than could be done remotely. the "su" command is much more used than the Windows equivalent "runas". TCP Wrappers is often installed by Unix admins to create ACLs on their boxes. Similar tools exist in NT and 2000, but are not often used (a how-to for W2K has even been published on this site a few months ago).

But then there are far more MCSEs than Unix-Certified professionnals, aren't there ?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/152/19217#19217
The Reality of Perception 2003-04-08
Wisconsin (1 replies)
The Reality of Perception 2003-04-10
blacklight
dont blame MS-blame these stupid poeple 2003-04-10
ab_s0248@yahoo.com
The Reality of Perception 2003-04-10
Anonymous
Patch Management 2003-04-11
mesmer
The Reality of Perception 2003-04-11
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus