, 2003-10-22
Expand all |
Post comment
Joe Average User Is In Trouble
2003-10-22
Anonymous (5 replies)
Anonymous (5 replies)
Joe Average User Is In Trouble
2003-10-23
faraonej@bellsouth.net (2 replies)
faraonej@bellsouth.net (2 replies)

When was the last time your mailbox got filled up by a Linux email worm?
Besides, just counting the number of vulnerabilities misses the point. A large number of Linux/UNIX/BSD vulnerabilities are local exploits, or ones only available to authenticated users. Another large subset are DoS attacks only, and can't be used to spread viruses or remotely compromise a machine. On the other hand, thanks to Microsoft's browser integration, weak security model, and use of RPC, *most* Windows vulnerabilities are remotely exploitable.
In fact, let me digress for a moment about RPC. *nix administrators learned years ago that RPC is risky. Hardly anyone lets services such as portmapper run on the open Internet anymore; they're just too risky. In fact, those services are mostly considered obsolete now, and rarely present a problem. Microsoft, on the other hand, still hasn't figured this out. Nearly every Windows machine runs with port 135 open to the world, just begging to be tinkered with.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/193/23342#23342