Domain: techpowerup.com
Stories and comments across the archive that link to techpowerup.com.
Comments · 261
-
Re:flashblock - javablock
Well, in Opera @ least?
You have the ability, BY SITE, per right clicking on a particular site, of turning on FULL BLOWN java, or JavaScript, on a per-site basis... for the rest?
(HOWEVER - In Opera's GLOBAL options though, TURN ALL SCRIPTING TYPES IT SUPPORTS, off... easy to do, & smart, especially online today, per this /. article)
I also believe that certain "addons" .xpi type, for FireFox (less secure than Opera is though, typically, year-in & year-out, iirc) allow this, on a PER SOURCE basis too!
Something to consider!
HOWEVER - for MORE SECURITY ONLINE?
See this URL:
APK "12 step program" 4 a secure Windows NT-based OS (2000/XP/Server 2003/VISTA):
http://forums.techpowerup.com/showthread.php?s=e63 53d948ca02c86dee6df077d9a9d18&p=375355#post375355
That's for a LOT more security tips/tricks/techniques, that work!
(... & have visible proof (score photo on the multiplatform CIS Tool) that you can secure Windows to such a HIGH LEVEL, even the *NIX users (of various LINUX/SeLinux & BSD folks) ran, & evaded posting their scores on that test of online security by the CENTER FOR INTERNET SECURITY)
See proofs here, for one example here, of my last statement above:
http://it.slashdot.org/comments.pl?sid=260975&cid= 20109707
Too bad, would have been GOOD to share info. w/ they!
Still, take a read of the 1st URL's techniques above, & be safe (or, rather, safer... a LOT safer, especially today, online)... that gives you 12 base steps to implement & follow that I guarantee are a LOT more comprehensive than 90% of the sites out there telling you "how to secure Windows"...\
Enjoy!
APK -
Re:XP isn't that bad: DO THIS? XP = GOOD!
"It's mainly the tight integration of the browser with the OS that is/was an issue. Don't use IE and don't run executables from unknown sources and 95% of the security issues go away. SP2 is actually a pretty decent OS." - by b0s0z0ku (752509) on Wednesday August 08, @12:13PM (#20157893)
Want to make more "security issues", go away, in 12 easy steps (and, I think you'll find this article below FAR MORE COMPREHENSIVE in that URL below, than most any you've SEEN online in 1 spot for securing a Windows OS, especially online NOWADAYS):
Per my subject-line/title above, & your quoted response? No problem, take a peek @ the URL below, & exercise its suggestions:
APK 12 step program for securing Windows NT-based OS of modern varieties (2000/XP/Server 2003/VISTA):
http://forums.techpowerup.com/showthread.php?s=f34 39c6a16f6f140e10d4d6d191c34e0&p=375355#post375355
Do what's in that URL?
And, w/in 1-2 hours of your time, you'll have YEARS of uptime, more speed, & stability, AND BE FAR MORE SECURE ONLINE!
Proof?? See this photo from the multiplatform test, CIS Tool, by THE CENTER FOR INTERNET SECURITY for my resulting score of 84.735/100 possible (default setups scores on say, XP? Will be WAY lower):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
That's as HIGH a score as I can achieve, & STILL be able to go "online" & do what's needed, & NOT get "bugged/hacked/cracked", &, IT WORKS!
How well?
Well, so much so, that everytime I have challenged the various users of various "flavors" of *NIX here @ /., they "ran", or evaded the test with b.s. (why not take it? I am fairly CERTAIN many did but did NOT like the results they saw, & that their systems were not as "(insert *NIX variant here) is more secure than Windows" was proven WRONG):
http://slashdot.org/comments.pl?sid=254685&cid=199 85487
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
http://it.slashdot.org/comments.pl?sid=243071&cid= 19690705
http://it.slashdot.org/comments.pl?sid=243071&cid= 19691091
http://slashdot.org/comments.pl?sid=240283&cid=196 22485
http://it.slashdot.org/comments.pl?sid=244821&cid= 19736881
http://it.slashdot.org/comments.pl?sid=245695&cid= -
Well, rather than spend? U CAN DO SOMETHING:
You MIGHT be right (I can see that from MS "business perspective on it", but you truly CAN secure Windows, & to such a level, even *NIX folks I challenged could not beat it)... read on, I guarantee, you'll be GLAD YOU DID (especially if you use what is in this post, from another URL I authored, on how to do so)):
"They say this now, when there is Vista to buy. It's just part of Microsofts standard strategy... Release new operating system, try and make the old one look bad." - by chatgris (735079) on Wednesday August 08, @12:18PM (#20157973)
Per my subject-line/title above, & your quoted response? No problem, take a peek @ the URL below, & exercise its suggestions:
APK 12 step program for securing Windows NT-based OS of modern varieties (2000/XP/Server 2003/VISTA):
http://forums.techpowerup.com/showthread.php?s=f34 39c6a16f6f140e10d4d6d191c34e0&p=375355#post375355
Do what's in that URL?
And, w/in 1-2 hours of your time, you'll have YEARS of uptime, more speed, & stability, AND BE FAR MORE SECURE ONLINE!
Proof?? See this photo from the multiplatform test, CIS Tool, by THE CENTER FOR INTERNET SECURITY for my resulting score of 84.735/100 possible (default setups scores on say, XP? Will be WAY lower):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
That's as HIGH a score as I can achieve, & STILL be able to go "online" & do what's needed, & NOT get "bugged/hacked/cracked", &, IT WORKS!
How well?
Well, so much so, that everytime I have challenged the various users of various "flavors" of *NIX here @ /., they "ran", or evaded the test with b.s. (why not take it? I am fairly CERTAIN many did but did NOT like the results they saw, & that their systems were not as "(insert *NIX variant here) is more secure than Windows" was proven WRONG):
http://slashdot.org/comments.pl?sid=254685&cid=199 85487
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
http://it.slashdot.org/comments.pl?sid=243071&cid= 19690705
http://it.slashdot.org/comments.pl?sid=243071&cid= 19691091
http://slashdot.org/comments.pl?sid=240283&cid=196 22485
http://it.slashdot.org/comments.pl?sid=244821&cid= 19736881
http://it.slashdot.org/comments.pl?sid=245695 -
TommyBoy: "Run Forrest: RUN!", lol!
LOL, tommy"StaleData/troll@trolltalk.com/talksAGoodGam
e ButCantBackItUpWithResults"hudson:
First of all - LOVE that email of yours: DESCRIBES YOU, perfectly!
Secondly?
I see that you're STILL avoiding taking this test & beating the CIS Tool 1.x score of 84.735/100 I obtained on a Windows rig I see?
Thanks, for SUCH a "good try" (not), & aren't you the guy who said this:
"Both linux and BSD eat Windows for lunch." - by tomhudson (43916) on Monday August 06, @11:41PM (#20138193)
WELL, back it up, then!
Take the test in the URL, & post your results vs. mine, for the results on a multiplatform test that runs on Solaris, BSD Variants (no OpenBSD or MacOSX though, a clear case of them having less development done for them), Linux & yes, Windows done by the CENTER FOR INTERNET SECURITY, in CIS Tool here:
http://it.slashdot.org/comments.pl?sid=260975&cid= 20109707
So - based on your 'big statement' above? PROVE IT, especially for security online...
LOL! You CAN'T, and you won't...
(You're not alone though - 21 others here failed to exceed the score I show Windows users how to obtain before you, on a multiplatform test for security)
Hey - & guess what? For all your BIG TALK??
You are now, #22... (hope you like that number @ least, lol!)
You've got that choice, exceed MY score, on the *NIX OS of your choice on a PC, or, you can attempt to outcode myself, & out write this app in the URL below!
Doing one yourself like it (uh, TommyBoy? It's mine, ME: "the guy who can't code", according to YOU, lol (so much for that as well)):
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
Also - did I EVER state Windows was the system that executed trades? No... but, I showed Windows Server 2003 + SQLServer 2005 (based on quotes) are the OFFICIAL RECORD of them, and do indeed, contain ALL RECORDS OF ALL DAILY TRADES @ NASDAQ & do so, @ 99.999% uptime ratings: Learn to read boy.
APK
P.S.=> "Big words", no production to back them though we see, from you tommyboy...
Typical! Mr. Hudson, with an email of "troll@trolltalk.com"?
Apparently?? That IS all you are, & YOU LIVE UP TO THAT NAME: A TROLL... very, VERY appropriate!
On your part??? We see in quotes above, lots of talk/big talk, but, lol... STILL no production to back your words!
(Tommyboy: Beat that score of mine (OR, the ability on YOUR part, to outwrite an app I wrote (doing one of the SAME KIND, but on YOUR part, doing a better job))...
Troll? You've been outtrolled, but with actual facts, programs, useful data, & production (not just "troll talk" hollow WORDS, lol!)... apk -
NO MORE STALE DATA TOMMYBOY, try this
Tommy"StaleDataUserTrollerBoyWithEmailofTroll@Tro
l lTalk"Hudson?
Go here, face up to it:
http://linux.slashdot.org/comments.pl?sid=261525&t hreshold=-1&commentsort=0&mode=thread&cid=20138729
vs. your statement there, of this:
"Both linux and BSD eat Windows for lunch." - by tomhudson (43916) on Monday August 06, @11:41PM (#20138193)
AND, this post of yours? Same damn thing, each time lol!
(That is literally what?? The 3rd time you repeated that, using STALE data, dated later than my own???)
Repetitively posting the SAME things here, does NOT "prove your point" posting your stuff 3x-4x now, anymore than it did the first time!
(& YOU had to post your stale data (vs. my own, it is 8 months out of date mind you, vs. what I posted as proof of MS' presence @ NASDAQ, using the SAME DATA your stale url's show, & Tandem mainframes being displaced by Windows Server 2003 + SQLServer 2005, & running 99.999% uptime on the job there?))
Listen - Go to that URL above I posted, & per what you stated there? Take that challenge... & beat my score! PUT UP, or, SHUT UP! Have some balls boy, try it.
(I cannot WAIT to see you RUN forrest, run, like 21 others here have)
By the by: In that URL above I post at the top of this reply here?
WELL, You are now bookmarked here as #22, by the way, because I STRONGLY SUSPECT, based on history here of 21 other *NIX heads avoiding that multiplatform security test for online security ratings, by the CENTER FOR INTERNET SECURITY, all used b.s. spinmaster evasions to avoid taking it (OR, their fear of posting lesser scores on it than I have gained rather): YOU TOO, will run from it, or evade it with some spinmaster b.s.!
HOWEVER, admittedly & FUNNY?
You ARE the first to TRY & use "STALE DATA", lol, vs. my own more current data proofs of MS' presence @ NASDAQ, & running into the 99.999% uptime range of stability, using SQLServer 2005 (not a BUG or reported vulnerability in its history, mind you, check SECUNIA.COM for that in fact), + Windows Server 2003 on the MDDS app run @ NASDAQ!
Your choice TommyBoy... that, or write a BETTER app than mine is, for the SAME purpose, shown below since you state I cannot code (you, the admitted "maintenance coder" lol)...
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
With one YOU did for the SAME purpose (since you said also I cannot code)... lol, IF you run from this test, ok?
APK
P.S.=> This out to be some fun, watching you "RUN, forrest, RUN!", from the challenge & test I noted above...AND, by the way, TommyBoy? GO to:
http://microsoft.com/bigdata
& TRY to disprove facts that show Microsoft Windows functioning @ ENTERPRISE CLASS LEVELS for all of the companies & projects running on SQLServer + Windows, while you're at it, lol! apk -
TommyBoy, no more stale data: Try this
Tommy"StaleDataUserTrollerBoyWithEmailofTroll@Tro
l lTalk"Hudson?
Go here, face up to it:
http://linux.slashdot.org/comments.pl?sid=261525&t hreshold=-1&commentsort=0&mode=thread&cid=20138729
vs. your statement there, of this:
"Both linux and BSD eat Windows for lunch." - by tomhudson (43916) on Monday August 06, @11:41PM (#20138193)
AND, this post of yours? Same damn thing, each time lol!
(That is literally what?? The 3rd time you repeated that, using STALE data, dated later than my own???)
Repetitively posting the SAME things here, does NOT "prove your point" posting your stuff 3x-4x now, anymore than it did the first time!
(& YOU had to post your stale data (vs. my own, it is 8 months out of date mind you, vs. what I posted as proof of MS' presence @ NASDAQ, using the SAME DATA your stale url's show, & Tandem mainframes being displaced by Windows Server 2003 + SQLServer 2005, & running 99.999% uptime on the job there?))
Listen - Go to that URL above I posted, & per what you stated there? Take that challenge... & beat my score! PUT UP, or, SHUT UP! Have some balls boy, try it.
(I cannot WAIT to see you RUN forrest, run, like 21 others here have)
By the by: In that URL above I post at the top of this reply here?
WELL, You are now bookmarked here as #22, by the way, because I STRONGLY SUSPECT, based on history here of 21 other *NIX heads avoiding that multiplatform security test for online security ratings, by the CENTER FOR INTERNET SECURITY, all used b.s. spinmaster evasions to avoid taking it (OR, their fear of posting lesser scores on it than I have gained rather): YOU TOO, will run from it, or evade it with some spinmaster b.s.!
HOWEVER, admittedly & FUNNY?
You ARE the first to TRY & use "STALE DATA", lol, vs. my own more current data proofs of MS' presence @ NASDAQ, & running into the 99.999% uptime range of stability, using SQLServer 2005 (not a BUG or reported vulnerability in its history, mind you, check SECUNIA.COM for that in fact), + Windows Server 2003 on the MDDS app run @ NASDAQ!
Your choice TommyBoy... that, or write a BETTER app than mine is, for the SAME purpose, shown below since you state I cannot code (you, the admitted "maintenance coder" lol)...
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
With one YOU did for the SAME purpose (since you said also I cannot code)... lol, IF you run from this test, ok?
APK
P.S.=> This out to be some fun, watching you "RUN, forrest, RUN!", from the challenge & test I noted above...AND, by the way, TommyBoy? GO to:
http://microsoft.com/bigdata
& TRY to disprove facts that show Microsoft Windows functioning @ ENTERPRISE CLASS LEVELS for all of the companies & projects running on SQLServer + Windows, while you're at it, lol! apk -
Ok staledataTommyBoy: Try this...
"Both linux and BSD eat Windows for lunch." - by tomhudson (43916) on Monday August 06, @11:41PM (#20138193)
Tom"StaleDataUserANDTroller"Hudson (LOL! with an email of "troll@trolltalk.com" no less?):
Let's compare then, per your statement!
The url below has a multiplatform test of their online security, ok, from a respected organization in CIS Tool (by the center for internet security) using the NIX of your choice on a PC then:
http://it.slashdot.org/comments.pl?sid=260975&cid= 20109707
AND, that I know you can see, as it is here on /. (unlike my being unable to reach your latest links, but I could see your first "stale one" vs. my more current data)
THIS IS COMPLETELY FAIR - go for it!
(Can you find a BETTER multiplatform test for this to compare with?? I'd take that, once you take this one, deal?)
That URL here @ /. has proof that a slew of posters that are *NIX heads (with URL's in those posts no less) that show avoidance of trying the test even, from /. here, or other NIX sites, 21x now or so (it posts my challenges for that in many of them I have done here, & elsewhere, to NIX folks).
(Oh, & by the way (as regards your puny attempt @ 'rattling my cage' about coding): That post also contains a post where my coding techniques were modded up here in fact, in "CODING FOR DEFCON" from last year, since DEFCON is here again, now, as of the date of THIS posting in fact)
(Ah, lol ... so much for your statement I don't write code, lol!)
LOL, if that was the case? Why would coders here (and guys like John Carmack post here, there is NO doubt of HIS skills in that area) mod me up then, on a topic about secure coding?
More proof? Ok (not stale either, like your data, lol):
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
DO A BETTER APP THAN THAT, for THAT purpose, ok? I wrote it... Ah, you won't:
After all, YOU are only a maintenance coder BOY, & YOU stated that, not I! lol... anyone can read what I wrote that actually has done the job, & will know otherwise (on that account, I would let others judge, not you)... That's by your own admission that is what you do, ALL you do, along with LOL, posting stale old data as evidences vs. my own is act as a MAINTENANCE CODER (not a lead or designer, not that maintenance coding is 'bad' per se, because you can LEARN much in doing it, but... there IS a large diff. in those roles, period).
ANYHOW - YOUR CHOICE (OUTWRITE MY APP WITH ONE FOR SIMILAR PURPOSE or, TAKE This multiplatform test of online security test)
Since you bust on saying I can't code (I do, in several languages, lol)?
WRITE A BETTER APP THAN THAT one is, for what it does, since this is an arena we can compare on (not MIS/IS/IT systems of non-online nature). Sure, you can say it's "shareware/freeware" & try to minimize it... here is my reply to that, before you TRY that b.s.:
Shareware/freeware, just like OS & other applications sold? NEED TO RUN ON A NUMBER OF HARDWARE/SOFTWARE PLATFORMS... db work, typically? RESTRICTED TO A UNIFORM HARDWARE SET by network folks (smart, but can limit portability for certain to other mixes of hardware &/or software)... so, so much for your staledata evasion spinmaster techniques, before you can utter them (easy to see your tactics are or would be).
Anyhow, as to the test vs. your words quoted above?
So... Will YOU also, avoid it via spinmaster b.s. OR other evasions, after you try it, and can't outdo my score on your NIX platform vs. Windows as I use?
Gee: History here has shown CLEANLY, that others *NIX folks, have avoided it, any way they could, 21 times now in fact!
(... AND, I strongly sus -
DON'T UNDERESTIMATE WINDOWS SECURITY... apk
As Dave Mustaine of MegaDeath said:
"A TOUT LE MONDE!"
I haven't posted on DefCon here, since last year here:
CODING FOR DEFCON:
http://it.slashdot.org/comments.pl?sid=158231&thre shold=1&commentsort=0&mode=thread&cid=13257227
BUT, this is my tiny "contribution" to your coverage of it here, this year (about security too):
"Ah, but NBC doesn't have to worry about hackers out for retaliation. What with their history of partnership with Microsoft (MSNBC) they must have the most secure computer systems on Earth." - by wytcld (179112) on Friday August 03, @08:03PM (#20109025)
Sure do, most likely, but... ONLY if their techs/admins set them up, @ the "client nodes" levels, ontop of perimiter defense protections (of course), this way, first:
APK "12 step program" 4 a secure Windows NT-based OS (2000/XP/Server 2003/VISTA)):
http://forums.techpowerup.com/showthread.php?s=e63 53d948ca02c86dee6df077d9a9d18&p=375355#post375355
AND, proof of the multi-platform CIS Tool 1.x (JAVA driven, & created by "the CENTER FOR INTERNET SECURITY") score possible, using those techniques noted above:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
I challenged several *NIX oriented sites, including folks here @ /., & other sites, in these posts:
http://slashdot.org/comments.pl?sid=254685&cid=199 85487
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
http://it.slashdot.org/comments.pl?sid=243071&cid= 19690705
http://it.slashdot.org/comments.pl?sid=243071&cid= 19691091
http://slashdot.org/comments.pl?sid=240283&cid=196 22485
http://it.slashdot.org/comments.pl?sid=244821&cid= 19736881
http://it.slashdot.org/comments.pl?sid=245695&cid= 19761821
http://linux.slashdot.org/comments.pl?sid=246583&c id=19779437
http://linux.slashdot.org/comments.pl?sid=252367&c id=19946243
LASTLY, & M -
Re:Switch!
"Is it the ads that bother you? Slashdot is adware, you know." - by catbutt (469582) on Thursday August 02, @01:30PM (#20089029)
I know, BUT... that? I can EASILY control, via simple HOSTS files entries, blocking ads, which bother me because they are using MY paid for bandwidth (sorry webmasters, I pay for this stuff JUST LIKE YOU, & I don't want ads eating my bandwidth which I pay for...).
Also? I don't want malwares/virus/trojans/etc. & you name it, from them either:
(YES, it happens too).
CHECK THIS, DATED TODAY 02/21/2007:
Microsoft apologises for serving malware
http://apcmag.com/5382/microsoft_apologises_for_se rving_malware_to_customers
This is by no means, a first either... it's happened QUITE A FEW TIMES the past few years!
So has this:
Computer Routers face Hijack Risk:
http://forums.techpowerup.com/showthread.php?t=257 34
AND, THIS:
SLASHDOT - DNS Root Server under attack:
http://it.slashdot.org/article.pl?sid=07/02/06/223 8225
AND, again: Sorry webmasters: Yes, I know many of you do NOT like this file of mine & others like it, but this is a BIG part of why I use one!
(Mine blocks nearly 100,000 known adbanner servers currently (lately, also many sites known as badware housers, per GOOGLE data on this, which I tend to trust)...
This practice some follow, as you know, like myself, allows users to speed up access to their fav. sites as well - THIS latter part though, speed up of access to fav. sites, the user has to setup, himself, but, not loading the banners does as well AND secures you against this very type of threat!)
I comment out an example of it in the file so the users have a template how to do it... & it's FULLY documented internally in my 'custom HOSTS file', on how to get around when a site changes its URL/IP equation too - very easy, ping & notepad.exe!
It is also FULLY alphabetized in addition to being organized into diff. sections, so hunting down servers that may already exist in it for blocking adbanners is easier!
AGAIN, WHY? Well, for the fact I pay for bandwidth, & do NOT trust BIND DNS totally per the above, & want the speed I can gain blocking ads and yes, doing my own resolutions to various sites (and, I can identify when its time to comment them off if they don't respond to test if their IP changed, OR they are truly down)
ALL OF THE ABOVE? WELL, I'm just NOT with that... simple, so I want CoNtRoL of it.
Also?
As far as MS doing this? BAD DAMN MOVE & especially THIS part:
MICROSOFT BYPASSES THE HOST FILE:
http://yro.slashdot.org/article.pl?sid=06/04/16/13 51217 [slashdot.org]
Read that... HOSTS files? They'll "bypass it"...
Which means you CANNOT control the ads period (locally stored on disk via caches or whatever, or if from online)...
I bought an OS & wares to use, not to be further advertised to, especially from a company that is ALREADY #1, but apparently, is looking for BAD PRESS via this adframework insertion & doing this to ANY of their wares!
(How long before the OS does this too I wonder)
I paid for it, right? I don't want the ads, & I won't buy ware that has them, & ones that especially limit my ability to CONTROL, period.
APK
P.S.=> Now, also? VISTA isn't going to do well, @ least before SP #1 (this is typical and cautious consumerism, & the masses are following this view largely, including business' & IT staffs making their recommendations)... It seems, like those folks? I am also going to wait out SP #1, as was -
Re:Security is no selling point SOME FYI 4U
"Unfortunately. XP is horribly insecure in the default configuration, and few companies have administrators that know enough to make it secure AND useable. Hence the widespread threat of trojans that companies are not even aware of." - by Opportunist (166417) on Tuesday July 31, @12:00PM (#20058601)
See this then:
http://forums.techpowerup.com/showthread.php?s=4e9 03947c5f2702d44e6171255963378&p=375355#post375355
For any/all admins that want to see a score like this one on their client-nodes in their LAN/WAN, for scores on the CIS Tool 1.x (THE CENTER FOR INTERNET SECURITIES' MULTI-PLATFORM ONLINE SECURITY TEST (which runs on BSD variants, Linux, Solaris (*NIX-s) & Win32 via JAVA)):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
It works vs. that which you mention Opportunist, & outlines how to get that score (84.735/100) via an easy to use simple 12 step guide!
APK -
Re:Not A Good Sign
"You may not realize it, but without concrete examples of attacks, software developers simply cannot comprehend attacks against their code that they can't do themselves" - by Effugas (2378) * on Sunday July 29, @05:33PM (#20034921)/--Dan Kaminsky
I'm with you, 110% on your statement in fact... a damn shame! People like he, & Joanna Rutkowska (another foreigner (Polish, like myself (but, I am a U.S. Citizen by birth/native))) have made a big difference lately in the world of computer security, & 'cutting them out'? NOT GOOD BUSINESS!
(I.E.-> I'd rather have folks like they BOTH contributing to the "general good", rather than the "general bad" & turning their talents to the 'dark side of the force', if you catch my drift!)
As far as apps getting better, on ANY front (not just bugs, but useability & features)? You are 110% correct... it's tough to spot diff. or better ways for any app YOU CREATED, by yourself, w/OUT user feedback (of ANY kind, on any issues)...
I built THIS app, with a TON of user-feedback during its 1997-2004 lifecycle of development (with users from 4 forums over time as testers), & the folks that helped me?
Man... THEY did a GREAT job (but, it's TOUGH taking critiques @ times too, but in the end, worth it (the ends justify the means)):
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
I could NOT have done that app (@ the present stage it is at, but I have not built more onto its actual CODE since 2004 really) WITHOUT folks telling me what they DID NOT LIKE (rather than what they liked, & I told them "Your criticisms are worth a TON of praise, so beat it up, & get back to me" etc. et al)...
APK -
Windows doesn't have to be "insecure"
"But, I'm sick and tired of all its insecurities. All of the stupid worms and viruses that I constantly need to worry about, and the pop-ups or pop-unders that hoses Internet Explorer as well as the security of your system" - by Anonymous Coward on Friday July 27, @03:36AM (#20007227)
Be 'sick & tired', no longer:
APK "12-step program" to a secure Windows-NT based (2000/XP/Server 2003/VISTA) PC:
http://forums.techpowerup.com/showthread.php?s=6d8 691c6bb63746854de7fc655435648&p=375355#post375355
SCREENSHOT PROOF OF CIS TOOL 1.x (multi-platform security test by THE CENTER FOR INTERNET SECURITY):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
Use that guide/roadmap in the 1st URL link listed above, & you'll get an 84.735 of 100 possible score on the Multi-Platform (runs on Solaris, Linux variants, & BSD variants (sorry, no MacOS X or OpenBSD ports yet though afaik) CIS Tool 1.x security analysis tool... that is the HIGHEST I can go, & still be online + do things I need to do!
APK
P.S.=> The guide's a BIT more "advanced" & complex than most you see online, & goes WAY farther into using the concept of "layered security" than most do as well, but it is about 1-2 hours of work for an experienced user @ most, for years of uptime, stability, extra speed, AND ABOVE ALL ELSE, security! apk -
Re:CIS TOOL 1.x MULTIPLATFORM SECURITY TEST BSD FO
LOL, yet another "downward moderation" by the EXTREMELY "Pro *NIX" crowd @
/., ROTFLMAO!
(Is this the BEST you have, mods & those with mod points? You're just "Vasserot the armless ambidextrian" @ this point, & thanks for helping me PROVE yet another point in favor of Win32 OS in fact, vs. *NIX variants! Read on...)
Apparently, this "down mod" (big deal, I have @ least 20 more that show me modded up here on these forums no less) IS really "all you have"...
AND, still, nobody from the *NIX world who always say:
"Windows is LESS SECURE THAN (insert *NIX variant here)"
Can surpass my score on this multiplatform test of ONLINE SECURITY, by THE CENTER FOR INTERNET SECURITY (especially the Linux/SELinux family which always RAN vs. my challenge above, & suggested BSD variants instead!)
Hilarious... lol, & the fact BSD variants are BINARY (or, configuration/setup init files) INCOMPATIBLE (good design? lol, not!)
APK
P.S.=> Also, TOO BAD your *NIX variants (from the BSD family code tree) are so "forked up" that OpenBSD apparently does not even RUN the FreeBSD version of this test... seems that Win32 wares like mine here:
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
Run across ALL Win32 OS variants, with no problems & NO NEED for porting or major rebuilds/recompiles either... &, lol, *NIX folks wonder WHY Windows NT-based OS' are the MOST USED on the planet with the most wares available! ROTFLMAO...
Above all?
Thanks for proving a point of mine here, in that this downward moderation (of my parent post) is the BEST YOU HAVE, vs. my score & photo thereof with roadmap guide for Windows users to secure themselves easily in 12 steps to a point that exceeds *NIX types period!
(I mean, well, otherwise, how could I have had 18x++ now, where *NIX folks say "Windows is less secure(able) than (insert *NIX variant here)" - none of them when confronted in a multiplatform test challenge exceeded my score?)
ALL despite the near constant diatribe rant of:
"Windows is less secure than (insert *NIX variant here)"
(Ah, lol, & yes - that's "too bad" that there is not an OpenBSD port of CIS Tool though, which imo, is PROOF that most *NIX's (except Linux imo) get almost NO development apparently & that OpenBSD users can't even run FreeBSD code no less - this is BAD period!)
There IS no doubt about it, that THIS binaries/config incompatibilities between *NIX variants is what helped to "KILL" UNIX out there, because, imo @ least?
Guys - today? We should have ALL been running some form of NIX, but, instead are MOSTLY running Win32 based OS (& of them, mostly the excellent Windows NT-based ancestry tree today).
(& this is what stopped/stalled *NIX dominant usage imo, & that allowed Windows NT-based OS to "take over", or does the world's computers in over 90%++ percentages NOT run some variation of Win32 based OS today, & for decades now?).
Face it fellas - & that is all you HAVE is your "mod points" @ this point!
(Which I could personally give a hoot about (and, it ain't much to give a hoot over, vs. facts I pointed out with proofs to my score on this multiplatform security test vs. your lack of them AND lack of a port of this ware as well as BINARY (or setup/config files) INCOMPATIBILITIES BETWEEN BSD VARIANTS (this is GOOD DESIGN? LOL, not!), which more *NIX heads helped me prove my points in, lol))... apk -
Re:CIS TOOL 1.x MULTIPLATFORM SECURITY TEST BSD FO
LOL! Clearly, yet ANOTHER case of *NIX having LESS SOFTWARES AVAILABLE FOR IT, vs. Windows NT-based OS... nobody wants to develop for something nobody uses (apparently, because that is what this is telling me):
"Hello windbag. All you need to do is point me at the OpenBSD version of the tool. I don't see it on their web site." - by Anonymous Coward on Thursday July 26, @10:44AM (#19996529)
Windbag? Funny - aren't I the one with clear facts above in challenges I issued to the entire *NIX variant community here on this site & elsewhere:
http://slashdot.org/comments.pl?sid=254685&cid=199 85487
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
http://it.slashdot.org/comments.pl?sid=243071&cid= 19690705
http://it.slashdot.org/comments.pl?sid=243071&cid= 19691091
http://slashdot.org/comments.pl?sid=240283&cid=196 22485
http://it.slashdot.org/comments.pl?sid=244821&cid= 19736881
http://it.slashdot.org/comments.pl?sid=245695&cid= 19761821
http://linux.slashdot.org/comments.pl?sid=246583&c id=19779437
http://linux.slashdot.org/comments.pl?sid=252367&c id=19946243
LASTLY, & MOST IMPORANTLY, THIS ONE (where LINUX penguins suggest testing vs. a BSD variant no less):
http://linux.sys-con.com/read/382946_f.htm
LOL, & ALL I GET HERE IS YET ANOTHER "EVASION/SPINMASTER B.S." EXCUSE OF "My little used OS doesn't even HAVE a test I can run on it, because no one develops for it!"... rotflmao!
I also provided backing photo proofs of my score:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
AND METHODS FOR WINDOWS USERS TO GET THE SAME SCORE for online security ratings as well:
http://forums.techpowerup.com/showthread.php?s=fe3 a450dc9f3055920edd0fcea17b27b&p=375355#post375355
Each time in the list of 18 url's or so, above?
I issued a CLEAR CHALLENGE, with backing facts, (and how to get my score no less for Windows folks to use) to the *NIX community here to outdo my score on a multiplatform test for online security??
ABOVE ALL ELSE - You are the one tossing names. -
CIS TOOL 1.x MULTIPLATFORM SECURITY TEST BSD FOLKS
LOL... more *NIX "big talk" about being "so secure"...
"You also forget the target demographic for OpenBSD: this is not for your Desktop, nor even for your high-load server. You can use it for that, but the niche in which it lives is firewall, NAT, transparent bridging. Places where security matters more than anything else. Sure, a bit more complex to set up, you need to work more, but this is not your moms OS." - by Corporate Troll (537873) on Thursday July 26, @04:51AM (#19993919)
Well, ok then: Take that OpenBSD setup of yours, & run this test on it:
http://www.cisecurity.org/bench.html
And see if you can beat this score on it (which was gained on Windows Server 2003 SP #2):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
Via this "12 step program" (methods used to obtain that score on a modern Windows NT-based OS (2000/XP/Server 2003 & yes, it works on VISTA too):
http://forums.techpowerup.com/showthread.php?s=fe3 a450dc9f3055920edd0fcea17b27b&p=375355#post375355
I have repeatedly challenged *NIX people to this test, 17 times now (this will be the 18th in fact) here @ /. & other sites (Linux oriented ones) & to date:
http://slashdot.org/comments.pl?sid=254685&cid=199 85487
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
http://it.slashdot.org/comments.pl?sid=243071&cid= 19690705
http://it.slashdot.org/comments.pl?sid=243071&cid= 19691091
http://slashdot.org/comments.pl?sid=240283&cid=196 22485
http://it.slashdot.org/comments.pl?sid=244821&cid= 19736881
http://it.slashdot.org/comments.pl?sid=245695&cid= 19761821
http://linux.slashdot.org/comments.pl?sid=246583&c id=19779437
http://linux.slashdot.org/comments.pl?sid=252367&c id=19946243
http://linux.sys-con.com/read/382946_f.htm
Not a SINGLE *NIX user has surpassed the score I obtain using a custom-hardened setup of Windows Server 2003 SP #2 fully hotfix patched... not a one -
Re:How about pulling a Mac?
"Window's primary problem is that it is prone to viruses" - by pkphilip (6861) on Wednesday July 25, @11:08AM (#19983569)
And, you're saying that there are NO Virus/Trojan/Malware/Worms etc. et al, for Linux/BSD/MacOS X (*NIX's in general)? If so, I can show you a TON of this, as well as vulnerabilities galore in most ANY *NIX, via relatively current data if required.
I am sure you will concede that, as well as THIS point:
Since Windows based OS ARE THE MOST USED ON THE PLANET ("90%++ of the world's computers" as the commonly accepted saying goes)??
Where do you THINK the virus/malware/trojan/worm creators are going to find the GREATEST ATTACK VECTOR SURFACE AREA???
Windows, of course!
(I'd do the SAME, were Linux/MacOS X/BSD variants the MOST USED OS THERE IS!) ... especially since Microsoft ships this OS family in a DEFINITELY "less secured than possible state" & this, I guarantee... EVEN ON VISTA (which IS an improvement in its default setup even over its ancestor/predecessor, Windows Server 2003, which I use here (the codebase initially for VISTA in fact))!
How can I make that statement - easy (because it is possible to futher security-harden a Windows NT-based OS (2000/XP/Server 2003, & YES, VISTA) far more, as follows & how WITH PROOF):
"So I don't fully buy your claim that windows is more secure than Linux overall." - by pkphilip (6861) on Wednesday July 25, @11:08AM (#19983569)
Well, see my last post in this thread, regarding the CIS Tool 1.x (a multi-platform test for testing AND SECURING, most ANY OS type online)... & see if you can exceed the score I obtained there of 84.735/100:
SCREENSHOT OF SCORE:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
HOW TO ACHIEVE THAT SCORE (step-by-step/12-step guide for securing modern Windows NT-based OS'):
http://forums.techpowerup.com/showthread.php?s=ff0 4f75f46a2d46c333ea33a44a8c2bb&p=375355#post375355
Between that set of steps, & NOT doing "stupid stuff" like loading ANY ware onto your rig, + practicing 'safe sex online' (lol, nerdy humor) via email etc.??
Well, doing that???
You keep "Virus/trojan/malware/worm free"...
E.G./I.E.-> I have not had anything like that happen to myself in more than 15 yrs. online now in fact, because I keep myself safe with some VERY COMMON SENSE techniques (like NOT using illegal filesharing circuits where a GOOD chunk of what is there in the way of binaries IS COMPROMISED with malware payloads, not using java/javascript/activeX controls/active scripting to just ANY website, not using IRC anymore (a haven for bad scripts infections), not opening emails from just anyone & their attachments especially, etc., PLUS, using the "12 step program" I noted above).
APK
P.S.=> ALSO - Keep in mind, those SAME "malwares" are keeping YOU, working... YOU, the network admin/engineer/tech, & IF you don't like it? Well, I am sure there are thousands to millions of Indian & Chinese folks that will GLADLY take your place in your job for you (outsourcing ring a bell)... apk -
Re:Hrm... OK, 1 last thing! apk
"the last time I tried to set up SELinux by hand, I nearly locked myself out of my own box. So I can see the appeal of a distro where these things are set up for me." - by NickFortune (613926) on Saturday July 21, @04:15AM (#19936341)
LOL! I truly DO KNOW THAT FEELING (via experience, especially when it comes to understanding user rights to the filesystem, the registry, & yes, even services on Windows NT-based OS')... NOW though?
I use this (I authored it):
APK "12-STEP PROGRAM" ON HOW TO SECURITY HARDEN WINDOWS NT-BASED OS (2000/XP/Server 2003/VISTA):
http://forums.techpowerup.com/showthread.php?s=372 6e3ec023eb0d850496c9f82b1ac92&p=375355#post375355 ... & it allows me to achieve an 84.735 score (of 100 total), running Windows Server 2003 SP #2 fully security hardened (via methods noted in the posting there in the URL above) on the multiplatform CIS Tool 1.x test (by "The CENTER FOR INTERNET SECURITY")!
SCREENSHOT OF MY SCORE ON THE MULTIPLATFORM CIS TOOL 1.x:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
(& I am certain my score is actually HIGHER than that (because the test does not account for hardware & software firewalls, antivirus/antispyware programs, etc. et al & the fact I KNOW IT MAKES 4-5 SMALL ERRORS in its analysis as well, which I can & have proven to the makers of this ware)):
Here is the screenshot of my score, to go along with the methods of hardening Windows, to show proof of the score... I have challenged BSD folks, SELinux folks, & other *NIX's as well & to date? NOT A SINGLE PERSON FROM THE *NIX CAMP HAS BEATEN MY SCORE...
"OK. Hope that answers your questions. Let me know if I missed anything and I'll see if I can help :)" - by NickFortune (613926) on Saturday July 21, @04:15AM (#19936341)
You've been very helpful, thanks, but I wonder if you'd take that test (CIS Tool 1.x for Linux) & see if your hardened setups can exceed the score I note above on the same test...
Thanks!
APK -
Re:Wonder when this will be an "important update"?
Microsoft is starting to let ME down!
I must admit that, especially lately (& I am a BIG proponent of Microsoft's Operating Systems, especially Windows Server 2003)...
Still, it makes me sad, but, nothing GOOD lasts forever!
They, to me @ least? Are MORE than just a business looking to profit - & they ought to think of THEMSELVES that way too! I think they used to, but this has been lost ("attitude reflects leadership" & look @ WHO leads MS now... sorry, I have NO respect for the guy, as far as THIS field is concerned @ least - he may be a "helluva guy" & all that, as I do NOT know him personally, but as far as comp. sci. is concerned, the forge in which his company deals in? Well... you judge!)
Anyhow...
Like the Roman Empire? The USA today strongly reminds me of its downfall, & the unadulterated GREED is only mirrored in "CORPORATE AMERICA" even moreso. Microsoft, though it pains me to say this? After reading this here today, & more here earlier this week? Well...
E.G. #1:
Microsoft's attorney's gave me shit once for using the word "Windows" in wares I wrote, making me recompile them (resource strings alterations only) renaming them using "for Windows" in their title (@ the height of their popularity no less around the year 2002)...
I did so, not THAT big of a deal. They are still downloadable (as single apps), such as this one:
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
SCREENSHOT:
http://www.techpowerup.com/downloads/screenshots/3 89.jpg
E.G. #2:
Me, a person they wanted to work for they, no less @ one point after that:
http://slashdot.org/comments.pl?sid=245971&cid=197 60473
They approached ME, not I they, mind you/no less! This latest stuff from them? It is REALLY "turning me off" to they...
BUT, MOST OF ALL, what is upsetting me about MS is that the other day HERE @ SLASHDOT?
Well, I "got wind" of Microsoft blowing off coders in THIS country (the USA, of which I am a tax paying citizen & coder), to go to Canada!
Greed is taking the wheel @ MS, this is ALL this shows me!
(They try to tell us here in the states, more b.s., trying to say the U.S. doesn't have great coders, we do, by the truckloads, but we can't afford to work for 1 U.S. Dollar per hour (exaggeration, or, is it?) like overseas coders will, gaining by the advantage of the exchange of our currencies value vs. theirs etc. et al) ... that upset the hell out of me, here:
http://slashdot.org/comments.pl?sid=245971&cid=197 60473
I got modded up here for it, & other coders agreed with me AS TO THE WHY OF THIS OUTRIGHT $HIT happening in my nation (THE USA)...
& Microsoft is "following the trend", pure greed (worse than ever before & the funniest part is? They don't HAVE to... they are still #1, for now @ least, but if this shit keeps up? Who knows!).
It bothers the hell out of me, but then again? Take a look @ the now leader of Microsoft, & YES, his nationality/racial roots, & it goes with the territory!
(And F-YOU to anyone that gives me shit about being 'politically correct', because that is the BIGGEST BULLSHIT OF ALL! First off, You're talking to someone that's heard "stupid polock" his whole life (but, I know better, so stuff like that doesn't bother me)... however, as a U.S. Citizen & seeing my right to FREEDOM OF SPEECH BEING SUBVERTED FOR SPEAKING MY MIND? Again: F-you!) ... that's all I have to say about that! Ballmer, I never EVER had a good feeling about he taking ov -
Re:Wonder when this will be an "important update"?
Microsoft is starting to let ME down!
I must admit that, especially lately (& I am a BIG proponent of Microsoft's Operating Systems, especially Windows Server 2003)...
Still, it makes me sad, but, nothing GOOD lasts forever!
They, to me @ least? Are MORE than just a business looking to profit - & they ought to think of THEMSELVES that way too! I think they used to, but this has been lost ("attitude reflects leadership" & look @ WHO leads MS now... sorry, I have NO respect for the guy, as far as THIS field is concerned @ least - he may be a "helluva guy" & all that, as I do NOT know him personally, but as far as comp. sci. is concerned, the forge in which his company deals in? Well... you judge!)
Anyhow...
Like the Roman Empire? The USA today strongly reminds me of its downfall, & the unadulterated GREED is only mirrored in "CORPORATE AMERICA" even moreso. Microsoft, though it pains me to say this? After reading this here today, & more here earlier this week? Well...
E.G. #1:
Microsoft's attorney's gave me shit once for using the word "Windows" in wares I wrote, making me recompile them (resource strings alterations only) renaming them using "for Windows" in their title (@ the height of their popularity no less around the year 2002)...
I did so, not THAT big of a deal. They are still downloadable (as single apps), such as this one:
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
SCREENSHOT:
http://www.techpowerup.com/downloads/screenshots/3 89.jpg
E.G. #2:
Me, a person they wanted to work for they, no less @ one point after that:
http://slashdot.org/comments.pl?sid=245971&cid=197 60473
They approached ME, not I they, mind you/no less! This latest stuff from them? It is REALLY "turning me off" to they...
BUT, MOST OF ALL, what is upsetting me about MS is that the other day HERE @ SLASHDOT?
Well, I "got wind" of Microsoft blowing off coders in THIS country (the USA, of which I am a tax paying citizen & coder), to go to Canada!
Greed is taking the wheel @ MS, this is ALL this shows me!
(They try to tell us here in the states, more b.s., trying to say the U.S. doesn't have great coders, we do, by the truckloads, but we can't afford to work for 1 U.S. Dollar per hour (exaggeration, or, is it?) like overseas coders will, gaining by the advantage of the exchange of our currencies value vs. theirs etc. et al) ... that upset the hell out of me, here:
http://slashdot.org/comments.pl?sid=245971&cid=197 60473
I got modded up here for it, & other coders agreed with me AS TO THE WHY OF THIS OUTRIGHT $HIT happening in my nation (THE USA)...
& Microsoft is "following the trend", pure greed (worse than ever before & the funniest part is? They don't HAVE to... they are still #1, for now @ least, but if this shit keeps up? Who knows!).
It bothers the hell out of me, but then again? Take a look @ the now leader of Microsoft, & YES, his nationality/racial roots, & it goes with the territory!
(And F-YOU to anyone that gives me shit about being 'politically correct', because that is the BIGGEST BULLSHIT OF ALL! First off, You're talking to someone that's heard "stupid polock" his whole life (but, I know better, so stuff like that doesn't bother me)... however, as a U.S. Citizen & seeing my right to FREEDOM OF SPEECH BEING SUBVERTED FOR SPEAKING MY MIND? Again: F-you!) ... that's all I have to say about that! Ballmer, I never EVER had a good feeling about he taking ov -
History's definitely with Win32, vs. all others
"Year of the desktop? Let's see:
1994: No
1995: No
1996: No
1997: No
1998: No
1999: No
2000: No
2001: No
2002: No
2003: No
2004: No
2005: No
2006: No
2007: No (pending)
So, though I may be going out on a limb here, I'm gonna say "no" for 2008." - by nobodyman (90587) on Friday July 06, @06:53PM (#19774321)
And, I am inclined to agree with you, as history is a great indicator of the future (part of my job the past 15 years now has been to use historical data as a predicator of the future really, & it works (database coder, for lack of a better expression, professionally in that timeframe))...
The fact you illustrate, remains true, & it's always been a "Windows world", the past 15++ years now, on the PC-front from workstations/home use rigs, up to server class midrange to enterprise servers. 90% of the world's computers running Windows based OS' says it all...
Personally, if there was an OS that was as ubiquitous as Windows is (providing me greater employment opportunity based on that ubiquity & flexibility) and its body of surrounding wares that ride on it? Trust me, I'd be on it, like "white on rice"... but, that has NOT occurred, per nobodyman's rather accurate analyses.
There's a reason most folks use Windows, & the *NIX camp has tried it as well ("seize the youth, & you seize the future" via academia, & showing poor students a "FREE" OS they can use vs. Windows):
"Everything begins @ home"... so much in life does in fact.
However, vs. the *NIX attempt @ 'seize the youth & you seize the future' @ academic levels - Kids learn on Windows PC's largely, EARLY ON, & love their games (which Linux does not have as large a body of as Win32 does, & not by a LONG shot) & these same kids go thru school using them as well, & become QUITE proficient in using these machines running Windows, so they are their OWN "tech support" largely if need be and quite good @ it.
Then, those same kids eventually get out into "Corporate America" & what do they find MOSTLY? Win32 based rigs, where they are quite expert on them by that point, & already a 'trained weapon' in that regard as well, no need for retraining them exists on personal computing related notes.
So, that said? Why on earth would business' change to Linux overall/wholesale, & create retraining costs, when a watch that runs (and well, witness NASDAQ using Windows Server 2003 RC2 + SQLServer 2005 (zero/0 bugs in its entire history no less as far as secunia data on it) running NASDAQ 24x7 365 days a year @ the fabled "5-9's" - 99.999% of stability & uptime) is in place w/ Windows?
It's nice to see an alternate like Linux out there though, because my roots are from the System V days on UNIX @ the "tail end" of the 1980's/early 1990's, & Linux is close enough to where I can jump into it & use it IF needed and has KDE which I admire & like actually (but, I have yet to see that need @ work (constantly/mostly @ least), OR @ home for long periods, because Windows MORE than does the job on ALL fronts as noted from work, to play!).
As far as security online, as well? I can show you Windows can be secured SO WELL, here:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
(84.735 of 100 perfect score on CIS Tool 1.x, a multiplatform java based gauge of online security from a respected organization & my photo of my score, via 1 hour worth of work downloading & installing + running this tool, & following its guidelines for better security (it actually HELPS YOU, help yourself here, on many of its counts in its test scoring (not ALL though))
How to do it? Here (step-by-step in a fairly easy to use guide):
http://forums.techp -
Put your money where your mouth is Zombie Ryushu
"Yes, Linux is more secure than Windows. We know that." - by Zombie Ryushu (803103) on Friday July 06, @09:25AM (#19766327)
Hmmm, I know OTHERWISE!
You see, I have challenged *NIX users here @ SlashDot repeatedly in this multiplatform test, downloadable in a minute's time & installable in a minute's time as well, & to run the test takes at most, 1 minute as well!
(I would like to see Linux &/or BSD takers on this test, & MOST hopefully, I would like to see SELinux kernel hook addons for MAC (mandatory access control), which is a feature taken after Windows no less in its security, on ACL (access control lists))...
Still, 12 times now? Nobody here, or on other Linux sites has surpassed my score on CIS Tool 1.x, which is downloadable here:
Fact is, I made this challenge 12 times now on slashdot... no takers - plenty of evaders though.
E.G./To Wit:
I have achieved a CIS Tool (The Center for Internet Security) 1.x score of 84.735 of 100, here:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
& THIS IS THE ROADMAP TO ACHIEVE IT (a "how-to" guide for Windows users, since everyone ought to know this stuff today imo, especially today/nowadays):
http://forums.techpowerup.com/showthread.php?s=c8c 5745a8042c4b2d9c2f29c47ed57bd&p=375355#post375355
(CIS Tool 1.x is from the CENTER FOR INTERNET SECURITY & the tool IS multiplatform, & runs on various *NIX derivants (Linux/SELinux kernel hook addons for MAC (Windows-like ACL), Solaris, BSD variants (sorry, no MacOS X version yet, but that's just a clearcut case of MacOS X having less softwares really than Windows does))...
So, bottom-line:
All I can say is, for all the *NIX user's 'bluster' of "Windows is less secure or less securable than (insert *NIX variant here)", it's all F.U.D. & Hooey... pure b.s!
Show me otherwise!
Take your *NIX variants, & beat that score... put your monies where your MOUTHS are!
(... Yes, you can TRY to "undermine/lessen the value" of my using a std.'ized test such as this one, but if you don't beat my score on it? Well... The Linux PENGUIN imo, ought to be a chicken... & the "BSD DEVIL" runs when the Win32 Angel comes around... prove me wrong!)
If you somehow do? Great...!
I mean that, because I would like to discuss your scores + how you achieved them on your *NIX variant, & the test only takes a minute to download/install/run!
I want photo proofs thereof though (I won't accept less than photo proof as I provide, sorry)!
We can ALL grow/gain here, especially HOME USERS of both types of OS (SELinux & OpenBSD/FreeBSD are ones I'd like to see here the most though, because they are touted as the "MOST SECURE" of the *NIX genre, even from Linux folks I challenged, but did not get beaten by in terms of this test's ratings system)...
HOWEVER, like any software? I have spotted "minor errors" the test makes, & I can prove this (from a Windows stdpoint no less, based on registry data &/or use of secpol.msc where it downscores myself, perhaps you NIX nuts can find the same) ... & it does NOT account for things like firewalls of ANY kind, or antivirus, but it is STILL a damn good test!
Thus, because I KNOW there are tiny errors (3-4 in this program)? I know my actual security rating's higher than my photo (84.735) too, based on that fact...
APK
P.S.=> The point is to compare & discuss this here... care to take a challenge, NIX nuts? apk -
Re:I call BS
"Wow. You miss obvious explanations for your personal problems" - by The One and Only (691315) * on Friday July 06, @12:57AM (#19763655)
No "wow" involved, I actually earn about $10,000 less per year, than I did prior to 2000, currently... typically, as you advance in ANY field & gain years of experience, you typically earn MORE... this is not the case anymore.
I am not 'starving', but then again - typically, by now? I'd have bought a new PC as well as this thing I just purchased 9 months ago (& I LOVE IT):
http://forums.techpowerup.com/attachment.php?attac hmentid=8374&d=1182926965
2006 Tiburon GT V6 std. shift...
(Best warranty in the business @ 10 yr./100,000 miles bumper-to-bumper, & 6 yr./60,000 miles on powertrain (engine & tranny), hauls A$$ bigtime, & has great reviews (no defects or recalls either)).
However, in the city I live in (literally, ranked 12th worst economically in the USA as of a few weeks ago by a study)? It's NOT that easy to find coding or network engineering jobs as it was in the mid to late 1990's, & if you have one (I still do)? You "hold on with your teeth" & save, instead of spend, just in case (of a "rainy day")...
It's truly an "employer's market" now, & they can get programmers/analysts/software engineers & network admins/engineers FAR cheaper nowadays than they used to.
Is it a "personal problem" for me? Look @ some of the other replies, & the fact my post was INITIALLY rated as a +4 modded upwards one, & tell me I am alone in my sentiments.
"and instead turn around to blame them on the political situation, which you rant about, pretty much without rhyme or reason" - by The One and Only (691315) * on Friday July 06, @12:57AM (#19763655)
There is no excuse for outsourcing U.S. jobs, other than greed. The U.S.A. & its corporate structure did FINE in years prior to this trend lately, & this trend lately? PURE UNADULTERATED GREED... & I do think the stockmarket is the root of it.
Government has stepped in on the working man before, hence my Air Traffic Controllers Union BUSTING by Ronald Reagan... so I have to ask a question:
Why doesn't the government help the working man out, for once, under the republican party? I know of examples where they have messed up the working man before (see Air Traffic Controllers example above)... but, not many where they have helped the working class.
And, little clue here? The working class is a HUGE segment of the buying public. The way things are being run now, is "short-term thinking"... sooner or later, you have a huge segment of the buying public making less & less, rather than more, & that means they will SPEND LESS - so, business' cutting off the working class' disposable income, only hurts them as well, in the long haul.
"even though it has little to do with whatever point you're supposed to be making." - by The One and Only (691315) * on Friday July 06, @12:57AM (#19763655)
Again: I was modded upwards, up to +4 initially... funny, it must be yourself with the reading comprehension difficulties - I suggest "hooked on phonics"...
APK -
Re:Vista==Home Entertainment System UNTRUE! apk
"Windows has never been a proper business system anyway..." - by flyingfsck (986395) on Thursday July 05, @11:08AM (#19754293)
I have to disagree with you here!
Especially regarding Windows Server 2003 SP #2 (or RC2 - the foundation code for VISTA no less) & SQLServer 2005 (which @ secunia.com, a respected website regarding security, has shown it has having ZERO/0 vulnerabilities in its entire history to DATE)... check for yourself, & see!
Also, NASDAQ (an INCREDIBLY "high tpm (transactions-per-minute)" environs has achieved the fabled "5 9's" of reliability using the combination I mention above (Windows Server 2003 & SQLServer), 365 days a year & 24x7 no less...
(Not trying to KNOCK you personally man, but it's a factoid you ought to be made aware of is all, beacuse apparently? You aren't!)
APK
P.S.=> As far as "home workstation usage"? I have achieved a CIS Tool 1.x score of 84.735 of 100, here:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
& THIS IS THE ROADMAP TO ACHIEVE IT (a "how-to" guide for Windows users, since everyone ought to know this stuff today imo, especially today/nowadays):
http://forums.techpowerup.com/showthread.php?s=c8c 5745a8042c4b2d9c2f29c47ed57bd&p=375355#post375355
(CIS Tool 1.x is from the CENTER FOR INTERNET SECURITY & the tool IS multiplatform, & runs on various *NIX derivants (Linux/SELinux kernel hook addons for MAC (Windows-like ACL), Solaris, BSD variants (sorry, no MacOS X version yet, but that's just a clearcut case of MacOS X having less softwares really than Windows does))...
Not a single taker from here @ slashdot 11x now, has beaten my score...
NOR, some Linux oriented magazine sites forums members either, have beaten that score (OR, even come close to it imo, because stock outta the box? Most any OS will score sub 20's, & I'd be willing to almost bet on that in fact, having seen unsecured Windows rigs take that test)...
So, bottom-line:
All I can say is, for all the *NIX user's 'bluster' of "Windows is less secure or less securable than (insert *NIX variant here)", it's all F.U.D. & Hooey... pure b.s!
Show me otherwise!
Take your *NIX variants, & beat that score... put your monies where your MOUTHS are!
(... Yes, you can TRY to "undermine/lessen the value" of my using a std.'ized test such as this one, but if you don't beat my score on it? Well... The Linux PENGUIN imo, ought to be a chicken... & the "BSD DEVIL" runs when the Win32 Angel comes around... prove me wrong!)
If you somehow do? Great...!
I mean that, because I would like to discuss your scores + how you achieved them on your *NIX variant, & the test only takes a minute to download/install/run!
I want photo proofs thereof though (I won't accept less than photo proof as I provide, sorry)!
We can ALL grow/gain here, especially HOME USERS of both types of OS (SELinux & OpenBSD/FreeBSD are ones I'd like to see here the most though, because they are touted as the "MOST SECURE" of the *NIX genre, even from Linux folks I challenged, but did not get beaten by in terms of this test's ratings system)...
There are "minor errors" the test makes, & I can prove this (from a Windows stdpoint no less, based on registry data &/or use of secpol.msc where it downscores myself, perhaps you NIX nuts can find the same, & it does NOT account for things like firewalls of ANY kind, or antivirus, but it is STILL a damn good test! I know my actual security rating's higher than my photo (84.735) too, based on that)...
The point is to compare & discuss this here... care to take a challenge, NIX nuts?
apk -
I will vouch for Windows Server 2003 SP#2 & wh
"The viruses are intelligently designed. I'm not vouching for Microsoft Windows." - by geoffrobinson (109879) on Tuesday July 03, @12:12PM (#19731855)
Well, I will vouch for Windows, but I will let the "center for internet security's" CIS Tool 1.x, do it for me, as far as how intelligently designed Windows IS, and how solid it can be, from an internet security standpoint - so much so, that 11x now overall, no SELinux, OR BSD users cannot beat the score I obtain on the multiplatform tool for testing securit online!"
I am vouching for Windows Server 2003 SP #2 fully hotfix patched as of this date vs. *NIX systems, & why?
Because I have posted this 10x on slashdot, & 1 other LINUX oriented site (especially directed @ SeLinux kernel hook addons for a Windows ACL-like level of security control, because Linux does NOT have that by itself, w/ out SELinux afaik):
Here goes, evidence below:
A challenge to take a multiplatform security test that runs on many a *NIX and Windows NT-based OS of modern variety (2000/XP/Server 2003) & how to get the score I did with an easy as possible roadmap in a URL below for doing so!
Run the CIS Tool 1.x, on your BSD/Linux (prefereably SELinux)/Solaris rigs, it is downloadable here:
http://www.cisecurity.org/bench.html [cisecurity.org]
And, takes minute to haul in, install, & run it in an attempt to beat my 84.735 of 100 on it (from a reputable organization, The Center for Internet Security)...
Go for it, & see if you can beat my score of 84.735 on a FULLY custom security hardened Windows Server 2003 SP #2 fully patched as of the date of this posting.
Photo evidence of my score is here:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg [techpowerup.org]
And, the same score I obtained, literally, yesterday, as well!
(After putting on the latest patches for Windows Update to my OS which I download & store here - but, nice part is? I'll never need them, because I GHOST this image once it is patched & scanned for malware/virus/trojans/rootkits etc. with the latest/greatest up to date tools for that purpose, & practice safe email practices & more like disabling potentially "deadly" things that can be exploited in browsers like ActiveX/Java &/or scripting (for sites that do NOT need it))
For Windows users' reference, all noted here & how to GET THAT SCORE:
http://forums.techpowerup.com/showthread.php?s=2aa c2d3ff16e9b8448875ee96e27d1ec&p=375355#post375355 [techpowerup.com]
(That's for the Windows users here to gain by).
Thing is - I'd like to see the *NIX users of all kinds beat that security test evaluation score for safety online & how well their systems are secured, as a more "concrete evidenece thereof" in fact, since the poster I am replying to is a "SHOW ME PERSON" (as am I)...
HOWEVER - here @ slashdot, where slogans & b.s. of ALL kinds are stated vs. Windows & Microsoft?
Well - I have challenged you ALL here repeatedly on this note 7 times now, this is the 8th here! ... & there is one @ another Linux oriented site as well (UBUNTU discussion, where BSD was suggested instead of Linux OR even SELinux, & I posted here in a PC-BSD post with an arstechnica article base behind it, on the note of security in the reply I posted this challenge to):
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923 [slashdot.org]
&
http://slashdot.org/comments.pl?sid=240283&cid=196 31141 [slashdot.org]
& -
Perhaps Its just gotten easier: It has & matur
"Windows has some of the best tools out there - software as a whole has matured to a level that there hasn't been anything "new" and its been mostly upgrades. No wonder the market has shifted. Just because there are more developers in other environments, doesn't mean the market has dried up, just that it has matured." - by cybrthng (22291) on Tuesday July 03, @02:47PM (#19733963)
Agreed, 110%, & great points you made. Windows wares are VERY solid nowadays, & I suppose it almost makes it a "rule of thumb" that after a decade on any given platform, such as Win32? You WILL have high-quality wares by the truckload, that are matured & solid!
Even shareware/freeware nowadays? Is of such quality, it would have rivalled if not exceeded in many a way, the commercialware of 5-10 years ago... imo, @ least!
(And, I consider myself somewhat of a "software connoiseur" of the shareware/freeware AND commercialware world...)
However, "not only am I a client of Win32 softwares in commercial/shareware/freewares, but, I am ALSO a 'developer member' as well" & I have been for over a decade in the freeware/shareware arena (that statement's all in reference/analogy to "THE HAIR CLUB FOR MEN", lol, bad attempt @ humor, but see the URL below for backing proof of it):
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
APK -
A little story about Healthcare from inside...
I worked for a privatized insurance underwriter, as a coder, for security (securing code they wrote changing it from VB6 to
.NET & specific apps for security like SECURE FTP AUTOMATED DATA SENDERS & MORE) & have seen the "holes" in that companies' setup, security-wise, & they ARE there still!
When I pointed out various inadequacies in their security, @ a client computer node level INSIDE THEIR NETWORKS?
I was chastised by the CIO and his henchman the main network engineer (even though they followed many of my suggestions, all backed by valid documentation from MS & the fact I was hired to help secure their programs (building SECURE FTP programs, improving broken softwares they had, & more) & literally, I was called "STUPID", no less for mere suggestions to mgt.!
(1 of which, the CIO, who had NEVER EVEN DONE THIS TYPE OF WORK HANDS ON, a major problem in many spots I have seen in the past decade now, & more, in professional environs)...
Yes, even though they took my advisement before (me, a coder there, improving their programmatic level security) regarding tools Microsoft provides to stop errors/abends in their network & more.
That was after suggeting some things from here to they, because they needed it:
http://forums.techpowerup.com/showthread.php?s=2aa c2d3ff16e9b8448875ee96e27d1ec&p=375355#post375355
Most of what's there, can be automated into logon scripts (.reg file merges) &/or ActiveDirectory Group Policies, in minutes TIME, only!
I suggested, do a testbox with this setup, run our apps on it, & test to be sure they all work (maybe a DAY's TIME or TWO, tops, of a single network engineer's time, for better security, all the way down to a client node level)
That was after the Network Admin. tried the OLDEST mgt. trick (former mgt. here, & mgt. again now as of the date of this post) in the book on me:
"Oh, it would cost too much to take the time to apply those"
& I shut him down there, via showing him .reg files & policies that could be spread in minutes across every node in their LAN/WAN system!
(As well as HOW the IP stacks work with ipnat.sys, tcpip.sys, ipsec.sys & more (covered in that URL above, search "CableGuy" there, after that dunderhead who had never REALLY done the job @ this level (pure hardware guy) tried to "outsmart me" on that note also... & as far as CISCO PIX? LOL, I had to point out his precious hardwares @ the time were NOT impenetrable, or invulnerable also, then & today, vs. various machinations).
I told him after ALL of that, & proving him wrong:
"Gee, I wonder what costs more: A day's work for security here, or your customers finding out you are RIDDLED with security holes here, that could expose their private healthcare data?"
Things that ARE easily applicable by network engineers (it's their job, after all) are in that URL above, & yes, they can be made to work just fine on today's modern Windows OS & webbrowsers for better security, & even on LANS/WANS of corporate entities' client nodes of all kinds.
After I left that company (for a better job & company), all what I stated WOULD occur for they...
Most of what I have in that URL above is/was later backed by documentations from Microsoft, after I had put the ideas in the URL out initially @ this company (which shall remain nameless - I have no reason to expose they to hackers/crackers is why I won't mention their name).
After that, per Ayn Rand's novel? "Atlas Shrugged", & I was Atlas... & Atlas moved onwards to diff. & better horizons.
APK
P.S.=> The keyword is PROFIT here... anything for a buck, & screw the chumps that invest in our product seems to be the keyword today, today in a world built not on great men BUT instead committees of crooks largely, imo @ least... apk -
Re:Microsoft found making PR-FUD-ing research
"I believe I am feeding a troll here......" - by redcane (604255) on Saturday June 30, @05:59AM (#19698293)
You believe incorrectly - I am only asking that *NIX folks run a test which acts as a "scientific control method" between diff. OS types (Windows NT-based ones, vs. Linux/SELinux bearing ones, preferably, Solaris, BSD variants etc. et al), so we can all gain by it hopefully, and to see if the *NIX variant users will put their monies where their mouth's are.
If any parties are guilty of "trolling"? It's those from the *NIX camps, that constantly state "(insert NIX variant here) is more secure or securable than Windows"...
"However using that tool cannot give you an apples to apples comparison of windows to any other OS" - by redcane (604255) on Saturday June 30, @05:59AM (#19698293)
In response to that? All I can say is, find us a tool that runs across multiple platforms, as this one does, that shows a user how to secure their system more as this one does no less, that is essentially the same test, from the same OEM/software publishing house, and we can run that as well, as a gauge of how well any kind of OS is @ secure-ability.
(This is the CLOSEST I can find - and, in addition to running THIS test, since it is the closest thing I can come up with as a scientific method of control, since it is the same tool by the same OEM for gauging security on *Nix's & Windows NT-based OS'? Put your monies where your mouths are, download it, run it, & post your scores... 10x now, not a one of you has!)
"Your photo evidence shows a score for "Registry Permissions"" - by redcane (604255) on Saturday June 30, @05:59AM (#19698293)
Well, *Nix has analogs (such as conf / etc. stuff, correct?) My guess would be THOSE are tested... & imo, but not experience admittedly, as I no longer keep ANY *NIX online??
SELinux might be the ONLY one that does OK here - it's the only one, afaik, that maintains somekind of analog to Windows ACL rights, in the SELinux kernel hooks "MAC" (mandatory access control) labels... this goes beyond chroot type setup on *NIX.
Thus, it would have some label-based type of protection on configuration files, above & beyond CHROOT in *NIX, & is most likely the analog tested.
BUT, try it yourself, find out, we can compare notes, deal?
"It seems it is scored on "Best practice" (that wording is from their site). Part of the point of hacking exploits is that "best practice" is a constantly moving target as holes are discovered and patched." - by redcane (604255) on Saturday June 30, @05:59AM (#19698293)
Absolutely - all these tests are, is gauges of (more-or-less, an analogy here) how good the driver (user/admin) is behind the wheel (the computer tested)...
So, that said? Let's see how good you guys are, since you constantly state "*NIX > Windows @ security" etc. et al...
"There are guidelines for writing secure systems, but they are only guidelines, not guarantees, yet they are "Best Practice"" - by redcane (604255) on Saturday June 30, @05:59AM (#19698293)
Did I ever state once there are ANY guarantees in this life on anything? No... in the intro. of the post where I show Windows users HOW to get the 84.753 score on CIS Tool 1.x I noted in the parent post of mine?? I state that right off (you apparently just skimmed & blew past it, shame on you):
http://forums.techpowerup.com/showthread.php?s=459 b08d1b7beb6bd8dafc7ab49844635&p=375355#post375355
Read the top of it, drink it in, & digest it... it states what you do, & don't skim thru & just post next time... & patches overcome the unknown ones, once they are patched (as far as vulnerabilities).
Care to debate the amounts of both on diff. OS types? When I looked, & I posted them here: -
Re:The really sad part.... NOT SO SAD: Try this!
"This is a great disservice to the whole computer industry" - by EmbeddedJanitor (597831) on Thursday June 28, @09:40PM (#19684441)
Well, ok... this isn't then - a challenge to take a multiplatform security test that runs on many a *NIX and Windows NT-based OS of modern variety (2000/XP/Server 2003) & how to get the score I did with an easy as possible roadmap in a URL below for doing so!
Run the CIS Tool 1.x, on your BSD/Linux (prefereably SELinux)/Solaris rigs, it is downloadable here:
http://www.cisecurity.org/bench.html
And, takes minute to haul in, install, & run it in an attempt to beat my 84.735 of 100 on it (from a reputable organization, The Center for Internet Security)...
Go for it, & see if you can beat my score of 84.735 on a FULLY custom security hardened Windows Server 2003 SP #2 fully patched as of the date of this posting.
Photo evidence of my score is here:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
And, the same score I obtained, literally, yesterday, as well!
(After putting on the latest patches for Windows Update to my OS which I download & store here - but, nice part is? I'll never need them, because I GHOST this image once it is patched & scanned for malware/virus/trojans/rootkits etc. with the latest/greatest up to date tools for that purpose, & practice safe email practices & more like disabling potentially "deadly" things that can be exploited in browsers like ActiveX/Java &/or scripting (for sites that do NOT need it))
For Windows users' reference, all noted here & how to GET THAT SCORE:
http://forums.techpowerup.com/showthread.php?s=2aa c2d3ff16e9b8448875ee96e27d1ec&p=375355#post375355
(That's for the Windows users here to gain by).
Thing is - I'd like to see the *NIX users of all kinds beat that security test evaluation score for safety online & how well their systems are secured, as a more "concrete evidenece thereof" in fact, since the poster I am replying to is a "SHOW ME PERSON" (as am I)...
HOWEVER - here @ slashdot, where slogans & b.s. of ALL kinds are stated vs. Windows & Microsoft?
Well - I have challenged you ALL here repeatedly on this note 7 times now, this is the 8th here! ... & there is one @ another Linux oriented site as well (UBUNTU discussion, where BSD was suggested instead of Linux OR even SELinux, & I posted here in a PC-BSD post with an arstechnica article base behind it, on the note of security in the reply I posted this challenge to):
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
&
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
&
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
&
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
&
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
&
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
& (BSD one below, no takers there either, from the "vaunted BSD most secure -
Re:Microsoft found making PR-FUD-ing research
"MY absolute favourite security falsehoods are the various ways "researches" compare one system security to anothers Such straight forward conclusions are impossible to make" - by catwh0re (540371) on Thursday June 28, @11:39PM (#19685369)
Well, ok... you have a point. Here is mine:
Run the CIS Tool 1.x, on your BSD/Linux (prefereably SELinux)/Solaris rigs, it is downloadable here:
http://www.cisecurity.org/bench.html
And, takes minute to haul in, install, & run it in an attempt to beat my 84.735 of 100 on it (from a reputable organization, The Center for Internet Security)...
Go for it, & see if you can beat my score of 84.735 on a FULLY custom security hardened Windows Server 2003 SP #2 fully patched as of the date of this posting.
Photo evidence of my score is here:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
And, the same score I obtained, literally, yesterday, as well!
(After putting on the latest patches for Windows Update to my OS which I download & store here - but, nice part is? I'll never need them, because I GHOST this image once it is patched & scanned for malware/virus/trojans/rootkits etc. with the latest/greatest up to date tools for that purpose, & practice safe email practices & more like disabling potentially "deadly" things that can be exploited in browsers like ActiveX/Java &/or scripting (for sites that do NOT need it))
For Windows users' reference, all noted here & how to GET THAT SCORE:
http://forums.techpowerup.com/showthread.php?s=2aa c2d3ff16e9b8448875ee96e27d1ec&p=375355#post375355
(That's for the Windows users here to gain by).
Thing is - I'd like to see the *NIX users of all kinds beat that security test evaluation score for safety online & how well their systems are secured, as a more "concrete evidenece thereof" in fact, since the poster I am replying to is a "SHOW ME PERSON" (as am I)...
HOWEVER - here @ slashdot, where slogans & b.s. of ALL kinds are stated vs. Windows & Microsoft?
Well - I have challenged you ALL here repeatedly on this note 7 times now, this is the 8th here! ... & there is one @ another Linux oriented site as well (UBUNTU discussion, where BSD was suggested instead of Linux OR even SELinux, & I posted here in a PC-BSD post with an arstehnica article base behind it, on the note of security in the reply I posted this challenge to):
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
&
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
&
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
&
http://it.slashdot.org/comments.pl?sid=241957&cid= 19662703
&
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
&
http://it.slashdot.org/comments.pl?sid=241913&cid= 19662485
& (BSD one below, no takers there either, from the "vaunted BSD most secure allegedly NIX there is upon suggestion by Linux users in the URL below it) -
Re:APKTools is shit.
Per your subject line?
I can show quite a few links, from the words of others from website's saying they're not:
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
Would you like them?
"Reimer was right. You need to hang up your little Delphi rollerskates and go home." - by Ayanami Rei (621112) * on Friday June 29, @01:40AM (#19686081)
Ah, I keep forgetting you are the "FAMOUS (yet anonymous) Ayanami Rei", lol, & you have the right gained by accomplishments in this field, that allow you to dispense advice & tell others how to live...
"ALL HAIL AYANAMI REI" & roll out the red carpet, for he has spoken!
ROTFLMAO!
APK
P.S.=> Apparently, Jeremy Reimer's hosting provider, siteground.com, recently, making Reimer remove posts on his website about myself says otherwise, & Shaw.ca, Jeremy Reimer's ISP/BSP chastising him for sending me harassing emails also says otherwise as well... & Jeremy Reimer + his friend's showing here on technical matters:
http://www.windowsitpro.com/articles/index.cfm?art icleid=41095&cpage=211#feedbackAnchor
DEFINTELY SAYS OTHERWISE, as I got the LAST WORD THERE... lol! apk -
Re:PUT YOUR MONIES WHERE YOUR MOUTHS ARE
As per usual, nobody from the *NIX world is exceeding the CIS Tool 1.x (by the center for internet security) score I had in my posts above here about how to secure Windows 2000/XP/Server 2003/VISTA (how-to, here):
http://forums.techpowerup.com/showthread.php?s=378 52b3b0b2148fe282a73c1e688efc1&p=375355#post375355
And the photo evidence of said score:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
Why is that? The CIS Tool 1.x test only takes like 1 minute to download AND run... no, I think for all the b.s. here I see about "Linux/BSD > Windows" in most all things, is just that: B.S.!
All anyone ever hears @ slashdot is things along the lines of"
"Windows is less secure than (insert *NIX variant here)"
HOWEVER, when it comes to the chips being on the table, and putting your money where your mouth is, and in this case, on a test of your online security developed by a reputable organization?
No takers!
(OR most likely rather, there are takers, but nobody beating that security level score of 84.735 on The Center for Internet Security's CIS Tool 1.x, downloadable here for Solaris, BSD, Linux, & Windows -> http://www.cisecurity.org/bench.html )
"My point is this: my coworker had her brand new vista laptop owned to the point of explorer repeatedly crashing on bootup after just two days of websurfing!" - by DocSavage64109 (799754) on Wednesday June 27, @10:46AM (#19662985)
Hey, Doc... 1 last thing about that point of yours though: Do you honestly think that a user that does not know what they are doing is limited STRICTLY to Windows based OS'? Do you HONESTLY think it could not be done to a Linux or BSD user as well??
Come on!
(I.E.-> That something like that, or like it, cannot happen on Linux/BSD/Solaris, etc. et al?)
Beg to differ, if you do...
APK
P.S.=> Thanks for the 6th or 7th time now of you *NIX guys, for ALL of your big talk, not showing me your systems score as more secure than Windows can be online... most people are "show me" people, and you are not satisfying that requirement from they... nuff said! apk -
PUT YOUR MONIES WHERE YOUR MOUTHS ARE
"I am not convinced, next please Mr Jones." - by b1ufox (987621) on Wednesday June 27, @08:44AM (#19661667)
I don't work for Microsoft (though I have been interviewed by they, & they came to me, not I to they):
Will a test, head-to-head, *NIX vs. Windows Server 2003 SP #2 fully patched, convince you? Try this, the CIS Tool 1.x, & see if you can beat my score of 84.735 on it (with you guys using SELinux or BSD variants even vs. my setup, since this test is "multi-platform" & runs across BSD variants, Solaris, Linux variants, & yes, Windows variants)):
http://www.cisecurity.org/bench.html
I think for all the *NIX 'braggadocio' of "Windows is less secure than (insert *NIX variant here)" I see/hear online? No one is willing to put their money where their mouth is, and I have made challenge, but with reason - so we ALL learn by it.
(In essence, in a Windows-based OS, like any other? To get security, you have to work @ it. In Windows 2000/XP/Server 2003/VISTA, you have to do these "12 steps", about 1 hour of an experienced user's time):
http://forums.techpowerup.com/showthread.php?s=378 52b3b0b2148fe282a73c1e688efc1&p=375355#post375355
To get this score (on the multi-platform CIS Tool 1.x test, by the "center for internet security"):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
An 84.735 score on it...
Secured operations online, on Windows no less, is quite easily doable (& to levels that FAR EXCEED VISTA, with just a wee bit of work, and plenty to gain/learn!)
I wish some folks from the *NIX world would take this challenge, & possibly exceed my score (since the "control method" in the test? IS THE CIS TOOL 1.x TEST ITSELF, & download url's links for it are inside the 1st url noted above!)
If they could do that? I would ask how & where they did not fail things on that test, & attempt to emulate them on Windows, getting an even HIGHER score (and, still be able to go online & do things of course).
We'd ALL gain & grow by it, but, unfortunately/again - no takers to my challenge! Perhaps the Linux mascot ought to be a chicken, instead of a penguin, eh?
LOL! Take that as a "good natured rib", because I really WISH we had Os' like today, 10-15 years ago, & I respect what Linux REALLY is: A 'socio-cultural technological phenomenon' that is a decent OS, created mostly by freely donated time, from a lot of talented people!
(The nice part is, it IS possible you guys CAN beat my score on this tool, because it literally HELPS YOU TO DO SO, but it is NOT "perfect" & definitely makes some errors imo & yes, I can prove it, & it does not account for things like hardware "NAT" (or true stateful inspection type) firewalling routers for instance, but it IS the BEST overall multiplatform test I could find @ least, from a reputable organization!)
APK
P.S.=> I wonder if anyone from the Linux (especially SELinux bearing distros), or BSD variants camps can get a better score on that test, than that...
In fact, I have repeatedly challenged anyone who uses those OS' to do so, here @ this site:
http://it.slashdot.org/comments.pl?sid=237507&thre shold=-1&commentsort=0&mode=thread&cid=19408273
&
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
&
http://slashdot -
Re:Odd...
"On the contrary, I'd expect it to be one of the best jobs ever; you don't have to do anything." - by MadUndergrad (950779) on Wednesday June 27, @02:14AM (#19659761)
Well, not nothing, but then, not much either... to make Windows 2000/XP/Server 2003/VISTA, VERY secure online!
(In essence, you have to do these "12 steps", about 1 hour of an experienced user's time):
http://forums.techpowerup.com/showthread.php?s=378 52b3b0b2148fe282a73c1e688efc1&p=375355#post375355
To get this score (on the multi-platform CIS Tool 1.x test, by the "center for internet security"):
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
An 84.735 score on it...
Secured operations online, on Windows no less, is quite easily doable (& to levels that FAR EXCEED VISTA, with just a wee bit of work, and plenty to gain/learn!)
I wish some folks from the *NIX world would take this challenge, & possibly exceed my score (since the "control method" in the test? IS THE CIS TOOL 1.x TEST ITSELF, & download url's links for it are inside the 1st url noted above!)
If they could do that? I would ask how & where they did not fail things on that test, & attempt to emulate them on Windows, getting an even HIGHER score (and, still be able to go online & do things of course).
We'd ALL gain & grow by it, but, unfortunately/again - no takers to my challenge! Perhaps the Linux mascot ought to be a chicken, instead of a penguin, eh?
LOL!
APK
P.S.=> I wonder if anyone from the Linux (especially SELinux bearing distros), or BSD variants camps can get a better score on that test, than that...
In fact, I have repeatedly challenged anyone who uses those OS' to do so, here @ this site:
http://it.slashdot.org/comments.pl?sid=237507&thre shold=-1&commentsort=0&mode=thread&cid=19408273
&
http://it.slashdot.org/comments.pl?sid=240571&cid= 19630923
&
http://slashdot.org/comments.pl?sid=240283&cid=196 31141
&
http://linux.slashdot.org/comments.pl?sid=240501&c id=19630965
(and, more from slashdot, especially the PC-BSD one that had an article from arstechnica as its base, because Linux users @ the URL below repeatedly suggested things like "if you want security, go BSD" etc. et al!)
And here, elsewhere on Linux sites:
http://linux.sys-con.com/read/382946_f.htm
(See comments #82, #81, #77, #76, #73, #69, #63, #62, #61, #58, #21, #11, #9, #8 there for my repeated challenges to 100's of viewers from the Linux world, yet no takers (or rather, no one challenged that met or exceeded my score & instead, they suggested BSD variants))...
Yet, & to date? No takers!
(Or rather, no one that outdid my score, that is (because I do suspect those that I challenged DID try, & the Linux folks ended up suggesting BSD, yet no one from the "penguin world" (or "bsd devils") could exceed that score I obtained on it))
For all the "(INSERT *NIX VARIANT HERE) is more secure than Windows" b.s. slogans online?
Nobody from that world is willing to try a test that runs on BSD (sorry, no MacOS X version available, a case of there being less software for Macs than there is for W -
Vista/Windows Server 2003 SP #2/XP CAN be secured!
"Vista is not considered suitable, the cost is huge per seat, and they figure that as long as they are retraining the workforce to use something, it might as well be something that is cheaper, more secure, and more reliable." - by NeverVotedBush (1041088) on Sunday June 24, @12:24AM (#19625447)
For reliability?
See my subject line, and some data about Windows Server 2003 & SQLServer 2005 (history of 0 vulnerabilities so far @ SECUNIA.COM for its ENTIRE lifetime now) & they run NASDAQ 24x7, 365 days a year, stable as titanium steel/solid as a rock (with the fabled "5 9's" of reliability 99.999 uptime).
For security??
See this data (it takes some doing, 1 hour of work tops for experienced users & a bit more for those less experienced, but an excuse to be MORE experienced in the doing of it, if they want to learn: Want to get a job done RIGHT? Do it, yourself, in other words), & it can be applied to ANY Windows OS of modern variety (2000 even, & XP too, in the majority of its points):
http://forums.techpowerup.com/showthread.php?p=365 996#post365996
& the score it gains on CIS Tool 1.x:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
It can & DOES far surpass VISTA's score "oem/out-of-the-box-stock" as it is setup by MS, & yes, even patched... with about 1 hour's worth of work on an experienced user's part!
Even Linux folks agreed with me (god forbid, lol), that my 14 points for securing Windows (has one small omission, the use of regedit.exe, part of CIS Tool's suggestions) works, here:
http://linux.sys-con.com/read/382946_f.htm
And, when I challenged ANYONE there to exceed my score using CIS Tool 1.x (84.735)!
It appears that nobody tried to (or possibly they did, but could not. I say that, because many suggested BSD instead. So, that said? I posted in the BSD post there the other day (PC-BSD related, here @ slashdot, by arstechnica news reporters)!
Yet again, the same challenge to slashdotters - NO takers, again! Evasions? POSSIBLY!
- or, possibly they don't care about security online!
(OR, that my post was buried in the deluge of posts here @ slashdot (imo @ least, the boards here are difficult to see all users points/posts imo, the only weakness here: The posters that come here though, like Bruce Perens, John Carmack (& others I RESPECT IMMENSELY for their accomplishments though)))
Anyhow/anyways - nobody taking my challenge or beating my score from the *NIX world on a test that runs on ALL platforms (thus, it is the "scientific method of control", the same test on all systems OS types this tool runs on)?
This only shows myself, & the planet, that all this "Windows is less secure than *NIX" is pure b.s., & all of them (yes, even BSD derivants like MacOS X etc. et al) out of the box stock, have holes or room for improvements (especially in terms of security & holes/vulnerabilities).
Still, anyone care to download & try CIS Tool 1.x (from the CENTER FOR INTERNET SECURITY), & exceed my score in the graphic above (84.735) from the *NIX world?
Here is its download (it is MULTI-PLATFORM, & runs on BSD (no MacOS X version though sorry), Linux, Solaris, & Windows):
http://www.cisecurity.org/index.html
Go for it, & good luck!
(I hope you *NIX (or windows guys too) CAN exceed my score, because I will ask how, & attempt to emulate this on Windows Server 2003 SP #2 fully patched, to get even stronger IF it is doable... &, we ALL can learn/grow & GAIN by such a test!)
Thanks!
APK
P.S.=> I can be reached @ apk4776239@hotmai -
Windows is as secure (or more) than SELinux or BSD
Check this out:
http://forums.techpowerup.com/showthread.php?p=365 996#post365996
& the score it gains on CIS Tool 1.x:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
It can & DOES far surpass VISTA's score "oem/out-of-the-box-stock" as it is setup by MS, & yes, even patched... with about 1 hour's worth of work on an experienced user's part!
Even Linux folks agreed with me (god forbid, lol), that my 14 points for securing Windows (has one small omission, the use of regedit.exe, part of CIS Tool's suggestions) works, here:
http://linux.sys-con.com/read/382946_f.htm
And, when I challenged ANYONE there to exceed my score using CIS Tool 1.x (84.735)!
It appears that nobody tried to (or possibly they did, but could not. I say that, because many suggested BSD instead. So, that said? I posted in the BSD post there the other day (PC-BSD related, here @ slashdot, by arstechnica news reporters)!
Yet again, the same challenge to slashdotters - NO takers, again! Evasions? POSSIBLY!
- or, possibly they don't care about security online!
(OR, that my post was buried in the deluge of posts here @ slashdot (imo @ least, the boards here are difficult to see all users points/posts imo, the only weakness here: The posters that come here though, like Bruce Perens, John Carmack (& others I RESPECT IMMENSELY for their accomplishments though)))
Anyhow/anyways - nobody taking my challenge or beating my score from the *NIX world on a test that runs on ALL platforms (thus, it is the "scientific method of control", the same test on all systems OS types this tool runs on)?
This only shows myself, & the planet, that all this "Windows is less secure than *NIX" is pure b.s., & all of them (yes, even BSD derivants like MacOS X etc. et al) out of the box stock, have holes or room for improvements (especially in terms of security & holes/vulnerabilities).
Still, anyone care to download & try CIS Tool 1.x (from the CENTER FOR INTERNET SECURITY), & exceed my score in the graphic above (84.735) from the *NIX world?
Here is its download (it is MULTI-PLATFORM, & runs on BSD (no MacOS X version though sorry), Linux, Solaris, & Windows):
http://www.cisecurity.org/index.html
Go for it, & good luck!
(I hope you *NIX (or windows guys too) CAN exceed my score, because I will ask how, & attempt to emulate this on Windows Server 2003 SP #2 fully patched, to get even stronger IF it is doable... &, we ALL can learn/grow & GAIN by such a test!)
Thanks!
APK
P.S.=> I can be reached @ apk4776239@hotmail.com in regards to your scores, if you do not have the ability to post your CIS Tool 1.x score on the web, & we can discuss your scores... everyone gains this way! apk -
IMPROVE WINDOWS SECURITY - PAST VISTA!
"The security aspect of things really hasn't changed much" - by Runefox (905204) on Saturday June 23, @11:36AM (#19620095)
Check this out:
http://forums.techpowerup.com/showthread.php?p=365 996#post365996
& the score it gains on CIS Tool 1.x:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
It can & DOES far surpass VISTA's score "oem/out-of-the-box-stock" as it is setup by MS, & yes, even patched... with about 1 hour's worth of work on an experienced user's part!
Even Linux folks agreed with me (god forbid, lol), that my 14 points for securing Windows (has one small omission, the use of regedit.exe, part of CIS Tool's suggestions) works, here:
http://linux.sys-con.com/read/382946_f.htm
And, when I challenged ANYONE there to exceed my score using CIS Tool 1.x (84.735)!
It appears that nobody tried to (or possibly they did, but could not. I say that, because many suggested BSD instead. So, that said? I posted in the BSD post there the other day (PC-BSD related, here @ slashdot, by arstechnica news reporters)!
Yet again, the same challenge to slashdotters - NO takers, again! Evasions? POSSIBLY!
- or, possibly they don't care about security online!
(OR, that my post was buried in the deluge of posts here @ slashdot (imo @ least, the boards here are difficult to see all users points/posts imo, the only weakness here: The posters that come here though, like Bruce Perens, John Carmack (& others I RESPECT IMMENSELY for their accomplishments though)))
Anyhow/anyways - nobody taking my challenge or beating my score from the *NIX world on a test that runs on ALL platforms (thus, it is the "scientific method of control", the same test on all systems OS types this tool runs on)?
This only shows myself, & the planet, that all this "Windows is less secure than *NIX" is pure b.s., & all of them (yes, even BSD derivants like MacOS X etc. et al) out of the box stock, have holes or room for improvements (especially in terms of security & holes/vulnerabilities).
Still, anyone care to download & try CIS Tool 1.x (from the CENTER FOR INTERNET SECURITY), & exceed my score in the graphic above (84.735) from the *NIX world?
Here is its download (it is MULTI-PLATFORM, & runs on BSD (no MacOS X version though sorry), Linux, Solaris, & Windows):
http://www.cisecurity.org/index.html
Go for it, & good luck!
(I hope you *NIX (or windows guys too) CAN exceed my score, because I will ask how, & attempt to emulate this on Windows Server 2003 SP #2 fully patched, to get even stronger IF it is doable... &, we ALL can learn/grow & GAIN by such a test!)
Thanks!
APK
P.S.=> I can be reached @ apk4776239@hotmail.com in regards to your scores, if you do not have the ability to post your CIS Tool 1.x score & we can discuss your scores... everyone gains this way! apk -
Going to have a nice chat with you): READ ALL!
"I think it's HILARIOUS to harass YOU online. Just you. Only you." - by StarKruzr (74642) on Friday March 30, @12:21AM (#18539431)
StarKruzr,
I looked you up @ slashdot, because of the lunacy you posted @ Jeremy Reimer's forums here about myself & yourself:
"Hi guys. I'm another Arsian who has managed to get entangled in APK's dumbassery" - StarKruzr Midshipman
You started it up with myself, everytime, & evidence of that is below - you kept it up here @ slashdot, after you did it at techpowerup.com forums, & lastly/lately @ WindowsITPro! Evidences of that are all over the web where you cannot edit it out or impersonate me, & they are below.
Same stuff I showed the police yesterday (and they told me I have a definite WIN vs. Jeremy Reimer & Jay Little on Aggravated Harassment AND Libel as well).
This URL (the same one Jeremy Reimer posted my families' home address in, & Evil_Merlin made threats vs. they in):
http://www.wowdailynews.com/pegasus/phpbb2/viewtop ic.php?t=4128&start=500&sid=837c7981b75f7ed3faaf3b da68f73b22
Listen starkruzr:
I never wanted any hassles with you, why are you trying to ruin your life over Reimer, when he is showing you he does not care WHO he takes down with him?
Heck, I did not even KNOW who you were, until you posted here bothering myself first (after you tried it @ techpowerup.com, noted below):
http://forums.techpowerup.com/showthread.php?s=889 edb5f1ee4cd22eee33bc580b0e190&p=207262#post207262
And started up crap with me. I knew you were an arstechnica member though, and sure enough: You are, & I caught you in your lunacy, posting as others no less (what you say I do? You all do, yourselves, as your std. practice/modus operandi).
I don't understand you - I had nothing going with yourself, whatsoever! Don't you understand that nut Reimer is obsessed with myself (is he gay or something? I don't get it!)
After all, your fellow arstechnica friends Jeremy Reimer &/or Jay Little, not until they began pursuing me all over harassing myself, & libelling myself in edited photos & .mp3 files they sung (stolen from southpark - Reimer's trademark is a lack of originality) here:
http://www.pegasus3d.com/download/apk.jpg
http://pegasus3d.com/download/apksong2000+++.mp3
pegasus3d.com/cgi-bin/ikonboard/topic.cgi?forum=1& topic=10
"Anyway the "APK" registered here is just an affectionate clone of the original. In fact I prefer him to the original." - Jeremy Reimer - March 25, 2005
& they many times harassing myself under "alternate guises" (as you had in your JTD/StarKruzr fiasco that got you caught @ techpowerup.com).
HONEST QUESTION:
"I think it's HILARIOUS to harass YOU online. Just you. Only you." - by StarKruzr (74642) on Friday March 30, @12:21AM (#18539431)
Don't you know, that your stating that, is only going to get you into trouble?
Why are you doing this to me? What had I EVER done to you?? I don't even KNOW you man! Why? Just because I have gotten the better of yourselves head-to-head, getting you to admit you are WRONG (as I did with Jay Little regarding what he said he was "an expert in", in Exchange Server (windowsitpro.com), & on Ramdisks (ntcompatible.com) & yourself lately here, on Windowsitpro.com, saying my points (only a couple you admit make sense, the portions on DLL's you noted I am correct on as well (read it, know it, drink it in & digest it for your own skillset - it is HOW IT IS, & how I state -
Care to compare CIS Tool 1.x scores anyone?
http://forums.techpowerup.com/showthread.php?s=e4
d 36eb2396773f558df8271fadcadf5&p=365996#post365996
That's a post showing an 84.735 score, using CIS Tool 1.x (highest I can get as of today) & methods I outline to achieve it, for Windows 2000/XP/Server 2003/VISTA users:
http://img.techpowerup.org/070618/APK14SecurityPoi ntsCISToolResult84735.jpg
That result was done using a tool I know of that runs across multiple platforms for a test of security online in CIS Tool 1.x (center for internet security)!
CIS Tool:
http://www.cisecurity.org/index.html
(& this test is the "scientific control method" in that it is the SAME test used across diff. OS/hardware platforms here)
CIS Tool runs on Linux, BSD (no MacOS X though), Solaris etc. et al (various *NIX variants), & Windows. Java runtimes are required (they were recently updated mind you, by SUN Microsystems).
Thing is, I have freely challenged Linux folks to run that test here & beat the score I had, shown above, here:
http://linux.sys-con.com/read/382946_f.htm
No takers, or rather, no respondents with scores exceeding mine on Windows Server 2003 SP #2 fully patched as of the date of the test I took it & yes, today.
They did suggest BSD - so I posted in regards to testing BSD vs. my score here, at slashdot:
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
Again, no takers (could be here though, it was buried too deep, slashdot's replies/forums system is way odd imo, by comparison to boards like this one imo, not as clean/easy to use/etc.).
Still, even from the "BSD" family (which is often noted to be the MOST SECURE UNIX etc., even by Linux folks (see the LINUX.SYS-CON.COM url above)), no takers.
All I know is this - I hear a lot of "Windows is insecure & (insert UNIX variant here) is more secure" etc. ... & yet, when it comes time to "put your money where your mouth is", on a test that runs across multiple OS platforms?
Nobody from the *NIX world has ever done so when I have asked them to try it @ least!
(& the test is sort of nerdy fun, you learn from it too, because it aids in securing yourself online).
And, the 14 points in the 1st URL above? For Windows NT-based OS like 2000/XP/Server 2003, & YES, VISTA??
They work!
(... & even *NIX folks agree many times they do)
I would like to see your scores here in fact, & IF you can exceed my score? We can all learn by it, & grow, as well as have a healthy competition in doing so!
Thanks! Any takers??
APK -
Re:'wierd link
http://forums.techpowerup.com/showthread.php?s=6c
9 40230061cf2255e2a54b64250e66f&p=365996#post365996
That is something you MAY find useful... because it outlines HOW to get the 84.735 score (of 100% perfect, impossible imo, & to be online OR do anything you may need to, servers-wise, online) on CIS Tool 1.x.
Download for CIS Tool 1.x (for Solaris, BSD, Linux, & Windows) is here:
http://www.cisecurity.org/index.html
For YOUR reference, & HOPEFULLY? Usage... see my P.S. below!
My photo verifying my score is here:
http://forums.techpowerup.com/showthread.php?s=6c9 40230061cf2255e2a54b64250e66f&p=366342#post366342
* Sorry about the Messiness of that last post, since you stated it was difficult to decipher the link url & the pertinent data within... & I hope you find this useful information (because of your stating you steer clear of Windows workstations).
APK
P.S.=> That all said & aside? Would you care to TRY the CIS Tool 1.x for you *NIX platform, here @ slashdot, & compare it to my score??
I posted a challenge for that here, today, @ slashdot:
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
It would be GOOD to see you there, and get your feedback on YOUR *NIX (Linux, Solaris, or BSD (NO MacOS X though)) version you use!
The test is ACTUALLY FUN, in a 'nerdy/geeky' way (and a good thing to do, because I think/feel you will find it VERY comprehensive, many things may be "old hat" to you, but I think/feel you may learn something from it also... I know I did!)...
LOL - put it this way: This challenge? It's about "putting your money where your mouth is", lol (good natured laff, not ribbing here), AND for myself/most importantly?
That is so I can see IF Linux/Solaris/BSD guys CAN actually do better than I have @ present, on this system (Windows Server 2003 SP #2 fully hotfix patched)... apk -
Re:'wierd link
http://forums.techpowerup.com/showthread.php?s=6c
9 40230061cf2255e2a54b64250e66f&p=365996#post365996
That is something you MAY find useful... because it outlines HOW to get the 84.735 score (of 100% perfect, impossible imo, & to be online OR do anything you may need to, servers-wise, online) on CIS Tool 1.x.
Download for CIS Tool 1.x (for Solaris, BSD, Linux, & Windows) is here:
http://www.cisecurity.org/index.html
For YOUR reference, & HOPEFULLY? Usage... see my P.S. below!
My photo verifying my score is here:
http://forums.techpowerup.com/showthread.php?s=6c9 40230061cf2255e2a54b64250e66f&p=366342#post366342
* Sorry about the Messiness of that last post, since you stated it was difficult to decipher the link url & the pertinent data within... & I hope you find this useful information (because of your stating you steer clear of Windows workstations).
APK
P.S.=> That all said & aside? Would you care to TRY the CIS Tool 1.x for you *NIX platform, here @ slashdot, & compare it to my score??
I posted a challenge for that here, today, @ slashdot:
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
It would be GOOD to see you there, and get your feedback on YOUR *NIX (Linux, Solaris, or BSD (NO MacOS X though)) version you use!
The test is ACTUALLY FUN, in a 'nerdy/geeky' way (and a good thing to do, because I think/feel you will find it VERY comprehensive, many things may be "old hat" to you, but I think/feel you may learn something from it also... I know I did!)...
LOL - put it this way: This challenge? It's about "putting your money where your mouth is", lol (good natured laff, not ribbing here), AND for myself/most importantly?
That is so I can see IF Linux/Solaris/BSD guys CAN actually do better than I have @ present, on this system (Windows Server 2003 SP #2 fully hotfix patched)... apk -
Re:'wierd link
That always comes down to WHO is setting the systems up & admin'ing them, can you concede this?
E.G.-> http://forums.techpowerup.com/showthread.php?s=784 c7caab0a4072b2e2cb96198eeb995&t=16097&page=2
It took me a while to figure out the link. I was looking for information on some poor configuration, but the link was to a mild flamewar. Then I got it. It's emotional kids setting up servers. Got it.
I'll concede that gamers and hackers aren't the best admins much of the time and fall prey to games, pranks, and exploits. They are the ones you tell you have penetrated their machine, here take a look this address; file://127.0.0.1/ I can see all the stuff on their hard drive. It's not amazing how many of these kids fall for it.
One of the comments in your link sums it up well.
"Never underestimate the ignorance of a noob.
In America we have Drive-Up ATM's with BRAILLE buttons." -
Re:Ok, I took your advice, & here is what I fo
"Feel free to source more than one security advisor. It may be helpful." - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
Good point & I'll agree (2nd doctor's opinions always are helpful):
(I didn't have time (got called into work to resolve an issue, but am home again now))...
"IIS secure? Apache secure? They both have exploits." - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
Yes, that's the very point I was trying to make...
"The number of exploits is one thing." - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
Yes, & there is apparently MORE reported on Apache Servers, up to 10 times more, per SECUNIA's data @ least.
"The number of exploited machines is another" - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
That always comes down to WHO is setting the systems up & admin'ing them, can you concede this?
E.G.-> http://forums.techpowerup.com/showthread.php?s=784 c7caab0a4072b2e2cb96198eeb995&t=16097&page=2
See that url, humor me, especially THIS one... there is a reason why, because it "backs up" what I said above... with quantified numbers!
I.E.-> There, on the CIS Tool 1.x test (runs on Solaris, Linux, BSD, Windows etc. et al)?
I put out a roadmap of how to get an 84.735/100.000, w/ verifying photo of my score... I have challenged Linux folks to beat it here:
http://linux.sys-con.com/read/382946_f.htm
No takers... or, no one could!
Today, on a BSD related post (since most of the Linux folks @ the URL above suggested BSD for security)? I put the SAME CHALLENGE FORTH to BSD users here @ /. (slashdot/root lol!):
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
Hopefully, there WILL be some "takers" this time, from the BSD world!
(That 84.735 score in the techpowerup.com url above? It is as good as I can get it @ least, on Windows... stock though?? Even Windows Server 2003 SP #2 only gets like a 20 iirc, out-of-the-box/oem stock!)
"To make you feel good, here is a current Linux exploit;" - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
Well, it wasn't about THAT to me, but... since you put it THAT way? This does a better job:
I.E. - Windows Server (9%) itself has less bugs and LESS CRITICAL ONES, than Linux 2.6 kernel builds (13%) do!
Windows Server 2003 Enterprise Edition @ SECUNIA
http://secunia.com/product/1174/?task=advisories_2 007
vs.
Linux's @ SECUNIA (2.6 kernel builds/latest):
http://secunia.com/product/2719/
"For workstations which visit the web, I avoid Windows. Just seeing the headlines is enough." - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
Heh, I don't... see the URL above from techpowerup.com!
Again - on how I note how to setup Windows Server 2003 SP #2 (default install IS workstation/pro, you add server tools as needed, on the fly during setup, OR later as needed) to get that CIS Tool 1.x score of 84.735...
"If you have any data on the number of non Windows bots in the herds, let me know. I'm looking for any data on the breakdown of OS on exploited bots." - by Technician (215283) on Wednesday June 20, @11:57AM (#19581243)
LOL, cool... you're a "data archivist", as am I (for stats & such for backing during debates)... which IS good!
(I just thought you were trying to "overwhelm & devastate me" w/ a flood of figures (and I a -
Re:Nonono, we don't fear incompatibility
"I don't care about the pointless "allow or deny pseudo security" - by Opportunist (166417) on Wednesday June 20, @07:45AM (#19577149)
Ok, how about this (real, quantified scores on the note of security then, using the Center for Internet Security's "CIS Tool")?
See this page, it outlines how to get a 84.735 score on Windows XP/Server 2003 SP #2 (both fully hotfix patched) with about 1 hour's worth of work (for years of stability, uptime, & peace-of-mind security online):
http://forums.techpowerup.com/showthread.php?s=784 c7caab0a4072b2e2cb96198eeb995&t=16097&page=2
My photo of my score is there (84.735)!
I also have recently challenged Linux folks to beat that score (I suspect many tried, & could NOT exceed it and in fact, they suggested BSD for security vs. it) here:
http://linux.sys-con.com/read/382946_f.htm
(HOWEVER - None took the challenge & again - they suggested BSD instead!)
So, in regard to that?
Well, today, I made a challenge to BSD users here today in fact, in regard to this as well, see here:
http://bsd.slashdot.org/comments.pl?sid=238993&cid =19578849
Since Windows Server 2003 is the base/underlying ancestor code used in VISTA? I would like to see how Linux AND BSD folks can do on it, & IF they can exceed my score on CIS Tool!
It is, afaik, the ONLY multiplatform online security test there is, that is THIS comprehensive AND coaches the tester into HOW TO GET BETTER ONLINE SECURITY (worth doing, imo @ least, how about you?).
Thanks!
(AND, good luck (the test is actually FUN and tells you how to help secure yourselves online, AND, on many an OS platform))...
APK -
Re:Linux, RAID 5, md
http://forums.techpowerup.com/showthread.php?s=51
8 %2074ee73e9a212bfbabbaba41cf36e3&t=26630&highlight =Ta%20ch
That's for you RICH...
God, I absolutely HATE how /.'s board engine CHEWS on URL's & they tell US to 'watch your URL's' for God's sake...
SLASHDOT - quit inserting the domain name or IP after the URL's we post then, & solve the problem!!!
(it screwed up in my longer reply to you above here -> http://hardware.slashdot.org/comments.pl?sid=23734 3&cid=19403671 )
APK -
Re:Linux, RAID 5, md
"It is very hard to follow the posts you reference." - by Rich0 (548339) on Tuesday June 05, @04:23PM (#19402653)
It is? How so?? The comparison was there, and a full chart with standings, type of machines used, & even photos per 'contestant' as to the proof of their results.
"Were the systems you benchmarked of identical cost? Did they have identical RAID configuration?" - by Rich0 (548339) on Tuesday June 05, @04:23PM (#19402653)
NO! Of course not... the idea in that test was to compare DIFFERENT disk types users on those forums used, to help folks construct as fast a system as they could for THEIR needs! ... Tell you what, answer that for yourself here (take a decent look @ it):
http://forums.techpowerup.com/showthread.php?s=518 74ee73e9a212bfbabbaba41cf36e3&t=26630&highlight=Ta ch
Search THIS in quotes specifically to show you the overall standings chart ->
"(ACCESS/SEEK DATA) "HDTACH 3 SCORE CHART" complete list 09-11-2006"
For access/seek standings...
& this ->
"(CPU USAGE DATA) "HDTACH 3 SCORE CHART" complete list 09-11-2006"
For CPU USAGE standings...
See for yourself!
(It's not that difficult to spot (many diff. kinds of systems were used, for comparison's sake between different possible disktypes and controllers (and RAID levels etc.) and were compared there)) ... & this was the point - to see what type of setups worked the best, in 3-4 major areas of disk usage (we did not test WRITESPEEDS however & I wish we had).
I think you mean did I do a "controlled test", testing MY rig only with the caching controller running & testing that (which I did in the URL above), vs. my NOT using this controller (CPU usage would be more on that, no questions asked, if I let the SYSTEM CPU drive the disks I/O processing here - the other machines evidence this for me from that test though).
At that URL above? You will see that the HDTach 3.x test results in favor of my setup(which favor the nature of work I do in coding to db engines (SQLServer 2005 & Oracle usually) & string processing work (HEAVY CPU EATER))are:
Seek/Access @ 8.8ms (vs. the nearest competitor hitting 12.6ms @ & farthest competitor hitting @ 17.6ms!)
CPU Usage @ 0% here (vs. the nearest competitor after that number hitting 3%, & farthest competitor hitting @ 11% CPU usage).
Quite the margin of orders of magnitude improvement are present via using HARDWARE Caching controllers on CPU usage, & also on Seek/Access, testing my type of setup vs. ordinary ones!
(On the seek/access? It's POSSIBLY from bursting data in out of cache onboard the controller, but I attribute this MORE to the fact I have 10k rpm disks in RAID 0, @ the time of that test though).
Anyhow - Read speeds on "PRT" (perpendicular recording technology) using drives (as they were NEW back then in 09/2006) kicked all other disktypes butt though... I came in midpoint of those tests in burst read & avg. reads.
(This makes sense though - the aereal platter density on PRT drives is better: More data per sq (insert measurement) & per head pass, is possible on reads especially!)
"I'm not debating that RAID-10 can be faster than RAID-5, and that a true hardware RAID can use less CPU than a software RAID." - by Rich0 (548339) on Tuesday June 05, @04:23PM (#19402653)
Ok, cool, because that was my point really. The test bears it out, cleanly. Tests of this nature, comparing hardware vs. software emulations of hardware based tasks run by the SYSTEM CPU, usually DO!
I also opted for disks (SATA 1 + 10k rpm RAPTOR X's by Western Digital, which were new when I got the machine, but 'old' by the time of this test (part of the comparison was to see how good SATA2 + "PRT" tech is, vs. older diskdrive types -
Re:Linux, RAID 5, md
"Under most workloads the software RAID will outperform hardware - as the host CPU will have spare capacity" - by Rich0 (548339) on Tuesday June 05, @12:06PM (#19398061)
?
See the URL below with actual test data I guess... I put it up for others' to reference. It shows otherwise (on systems used for coding & DB engine serving (SQLServer 2005 MOSTLY, sometimes Oracle, but not lately on this job)).
I keep sample sets of data here & project setup JUST LIKE (as much as possible) the one @ work. So I can put in O/T on my own, research/testing, & also while I work from home (2-3 days a week via TS/Citrix/Remote Desktop).
(It's ALL due to the nature of my work, string processing & coding? Tears UP my CPU, hard - it always depends on the nature of work you are up to, like so much else does!)
"(especially if you spend a fraction of what you save on a faster CPU). Sure, maybe the latest and greatest $2000 adaptec card will do a little better, but is this a 16-CPU DB server? - by Rich0 (548339) on Tuesday June 05, @12:06PM (#19398061)
I spent $250 on my Promise Ex8350 SATA1/SATA2 128mb ECC RAM caching controller w/ an Intel I/O subprocessor on it: this is CHEAP, compared to high-end Adaptec solutions in the ScSi world.
Additionally, per these posts of mine (w/ requested benchmark data in them for SanityInAnarchy's reference (parent poster)):
http://hardware.slashdot.org/comments.pl?sid=23734 3&cid=19393291
&
http://hardware.slashdot.org/comments.pl?sid=23734 3&cid=19393157
In response to SanityInAnarchy (655584) the parent poster in favor of software RAID? I disproved (hate to say it) the statements he made that CPU usage on software RAID's is "not much more" than using hardwares...
After all: My showing 0% CPU usage, vs. 3%-11% in tests he wanted to see using HDTach 3.x, show a 300% - 1100% orders of magnitude savings of CPU usage alone!
If you guys want to debate it, fine... all I can say is, "argue with the numbers"... & like usual, it depends on what you're out to do really, like so much else in life.
(I did this setup, using a Promise Ex8350 128mb ECC RAM caching controller, due to what I outlined is the nature of work I do (heavy string processing, which is VERY cpu intensive, & coding generating many temp files during compile/recompile cycles) & why I want as high-performance of a system as I can afford, on ALL fronts if possible!)
See, I actually DO need (and want of course) this cpu savings using a Promise Ex8350 128mb ECC RAM controller w/ an Intel I/O subprocessor CPU on it (offloading my dual core AMD AthlonX2 4800+ cpu I have here, regardless of the NT-based OS' kernel component "process scheduler" sending threads off to less saturated cores if/when needed).
Why?
I HATE "SLOW" (purely relative term), & to me? Time = money in delivery schedules, etc. et al, & the biggest slow up on a system typically, is on disk especially!
Again, since my work deals in it quite heavily, I "feel the need, the need, for SPEED"!
So, I want fast Access/Seek as well, which the cache RAM on the controller helps me gain, as well as 10k rpm rates on my WD "Raptor X" diskdrives in RAID 6!
(See, due to the nature of my work? The burst and READ speeds don't matter as much, it's more WRITESPEED that matters to me & this is accounted for by this controller, as it EXCELS IN WRITES!)
If you look @ the HD Tach test we did though, here (for your reference), & if READ SPEED is of import to you, & burst reads especially? "PRT" using disks of SATA 2 nature are for you:
http://forums.techpowerup.com/sh -
More Data: NOT just CPU usage 0%, but 8.8ms Access
Oh, additionally?
I won in the Access/Seek too, 8.8ms in the test below, not just in 0% CPU usage!
AND, by BIG margins (due to 10k rpm "Raptor X's" in RAID 0) on that test imo, more than the controller really (unless it was bursting data out of the 128mb of ECC Cache RAM this controller uses)!
(CPU usage category where my system was showing 0% (vs. others ranging from 3% - 11%)... many orders of magnitude of gain in fact, especially if viewed in terms of percentages!)
Once more, the URL of HD Tach 3.x test again for your reference:
http://forums.techpowerup.com/showthread.php?s=518 74ee73e9a212bfbabbaba41cf36e3&t=26630&highlight=Ta ch
Enjoy!
"Great. Did it cost you more than an upgrade to a dual-core CPU? Or a whole separate processor? Or the difference between a single-core and dual-core, or between 32-bit and 64-bit?" - by SanityInAnarchy (655584) on Tuesday June 05, @01:35AM (#19392311)
About the same iirc... about $250, iirc, direct from Promise.
(Again, due to the nature of work I do in Coding & DB work, heavy diskbound activity usually (many files generating during compile/recompile cycles) plus serving up some files as well here too? I like & need FAST access & seeks mostly. Bursting is not something I am worried too much about, I rarely 'burst' read huge amounts of data)
"Or what about a whole separate computer? Just have a dedicated fileserver with enough CPU to handle the RAID, and connect to it over gigabit?" - by SanityInAnarchy (655584) on Tuesday June 05, @01:35AM (#19392311)
I have a 2nd machine here that acts as a SQLServer (2005), to do emulations of work related stuff with sample datasets on it. P4 3.2 ghz 1gb RAM, WD 36gb 10k rpm 8mb buffer generation #1 Raptor... all I need on it really, running Windows Server 2003 SP #2 & SQLServer 2005.
"I would say that, if you now have a lot of spare CPU cycles, you've wasted your money. I could be entirely wrong -- maybe you have done the benchmarks, and maybe you do have the kind of insane load it would take, but most of the time, hardware RAID is a waste." - by SanityInAnarchy (655584) on Tuesday June 05, @01:35AM (#19392311)
I don't know if you write code or not, or manipulate files (I do, quite a lot, much of it being string related & many @ once)? String parsing & such takes up LARGE amounts of CPU power. Coding does quite a bit of that, but more often here, it is in editing files (stripping HTML chars out, getting only RAW .txt out of it, & more (list goes on, hugely)).
I generally "tear up" cpu pretty badly in the nature of my work - not "TONS" of spare cycles left quite often on CORE #1 (AMD CPU Athlon X2 4800+), but the process scheduler takes threads from other process' (child & parent ones) & sends them to CORE #2 here, as needed.
Having this controller, with a hardware based Intel I/O subprocessor on it, saving SYSTEM CPU cycles as it does, WAY over "normal" setups (most of them, per the url test I directed you to), helps here, especially due to the nature of my work (coding & lots of string processing in files).
Gotta love Windows NT-based OS' for this (had thread model, TRUE smp enterprise ready threading @ kernel level/Ring 0/RPL 0, far before Linux did (the Linux initial "usermode threads" don't really count, as they resolved out to a single thread in kernel mode round robining to it... this is WHY Linux has 'true kernel mode threads' now, to be SMP/enterprise class OS ready in fact!)
Anyhow... you asked for benchmarks, you got 'em!
I have done them, see the URL above in THIS post, & my other reply (between the two of them, you have actual documented data & tests against many others, including "PRT" using disks (they ROCK on reads, as you will see)).
APK -
Re:Linux, RAID 5, md
"It's not significantly more." - by SanityInAnarchy (655584) on Tuesday June 05, @01:35AM (#19392311)
Well, my system showed 0% cpu usage on HDTach 3.x, here (vs. others that used std. SATA & IDE disks, that tore up CPU @ levels ranging from 3% - 11%... if viewed in terms of percentages on that account, cpu usage? I have many orders of magnitude over them):
http://forums.techpowerup.com/showthread.php?s=518 74ee73e9a212bfbabbaba41cf36e3&t=26630&highlight=Ta ch
(Alectaar is who I posted as there, & at the time, I was using a RAID 0 setup (as it took me time to buy more of these WD Raptor X disks for RAID 6 which I run now))
Search this on that page to help you find the overall chart there, faster:
(CPU USAGE DATA) "HDTACH 3 SCORE CHART" complete list 09-11-2006
See for yourself there.
Again - If CPU usage savings is viewed in terms of percentages? I actually DO save many orders of magnitude over others chewing up 3% - 11% of their CPU's there, per that test's results.
I post it for YOUR reference, & those of others! Especially since you asked for benchmarks data.
"Yes, it's more, but it's kind of like disk compression -- a filesystem running lzo compression, and doing it properly, will likely be FASTER than the same filesystem without compression, because even with all that CPU, it's still disk-bound." - by SanityInAnarchy (655584) on Tuesday June 05, @01:35AM (#19392311)
Oh, that is possible, I have seen it using NTFS compression: Filesizes on disk are smaller, & if defragged well? The compression/decompression process is SO fast on today's CPU's, that 'lag' is offset by the tinier filesize (especially on HIGHLY compressable data types, not .exe's (I leave these uncompressed usually) but data I crunch is like .txt for instance & other documents + highly compressible things in general - for just the reasons you hit upon!)
Thus, you may actually be better off running compressed disks, with tinier files to read UP from disk (this is not good for WRITES though, bear that in mind, compression does make you take a HIT there though).
"I'd have to see benchmarks. But remember, it's a performance/price ratio..." - - by SanityInAnarchy (655584) on Tuesday June 05, @01:35AM (#19392311)
Well, you have a GOOD set up there, comparing my SATA 1 diskset (I have additional SamSung SATA 2 stuff now ontop of the RAID 6 array, but they are for storage here mostly), to others using perpendicular recording disks (great for reads)...
My setup knocked them out for CPU usage, bigtime, because of the Intel I/O cpu on the caching PROMISE Ex8350 controller I use, & did really well (I was surprised, even against other categories of disk like SATA 2) on reads too.
READS (avg. & burst) I came in midpack - perpendicular recording technology drives on SATA 2 absolutely ROCK on reads. Even my 128mb ECC RAM caching controller running WD "Raptor X" SATA 1, 10k rpm drives (with 16mb buffers onboard the diskdrives in RAID 0 even) can't beat them in THAT capacity.
PRT is superior stuff, & newer, basically & better (for reads)!
Writes, I KNOW this setup would take them too, but iirc, we did not test writes though. This controller EXCELS @ reads!
APK -
Re:alternatives GETTING BACK TO YOU giorgosts
First off, thanks for replying & sorry for my late reply (busy & it's late now, here goes):
I tried it, & didn't see it! NO PROBLEMO here, & I checked for "error #3" you mentioned, on Mr. Zalewski's actual referring page...
SOME BACKGROUND INFO. HERE (I assumed you were on Win32 yourself by the by, like I am) FOR ANYONE WHO TRIES THIS TEST ON A WIN32 RIG & OPERA:
Here I am running Windows Server 2003 SP #2!
(A personally 'security-hardened' model I have been working on for many years since the NT 3.5x days onward to this version of the OS)
It has been way, WAY hacked up for security via things like:
1.) IP security policies (modded AnalogX one, very good)
2.) SCW was run over it first to help security it (SCW = security configuration wizard, & it's pretty damn good believe-it-or-not, @ least, as as starting point)
3.) PLUS, this version of the OS has a hardened IE6/7 by default (which can be duplicated on other Win32 OS versions, because it mainly just does what I have been doing for a long time & noted by myself earlier, in stuff like turning off ActiveX & scripting of all types by default)
4.) General security policies in gpedit.msc/secpol.msc
5.) Tons of security & speed oriented registry hacks (reconfiging the OS basically - stuff like you might do in etc in UNIX/LINUX I suppose)
6.) AND std. stuff like AntiVirus (NOD32 latest) + SpyBot as my resident antispyware tool running in the background!
7.) Many services I do not need are either cut off OR secured in their logon entity to lower privilege entities (from default, near "ALL POWERFUL" SYSTEM, to lesser ones like NETWORK SERVICE or LOCAL SERVICE), see this URL where I did a lot of research for a prebuilt list for another forums, to see how/why this works:
http://forums.techpowerup.com/showthread.php?s=518 74ee73e9a212bfbabbaba41cf36e3&t=16097
(And, of course, the user feedback on its effectiveness, as well as MacOS X, which uses the same general principals)
8.) Plus good email client practices like using .txt mail only, no RTF or HTML mail, not opening or allowing attachments unless I know the person (still gets email scanned though)))
As is now? I score an 84.735 on the CIS Tool 1.x (Linux, MacOS X, Solaris, & other OS models ports of this are available too by the way - not really "ports" strictly speaking, they require JAVA to run), from "The Center for Internet Security" here:
http://www.cisecurity.org/bench.html
Ah man... There's SO MUCH MORE I do to secure this, but too much to list really!
(I am sure I am overlooking some stuff, details & such - things like the fact I use a LinkSys/CISCO BEFSX41 "NAT" true firewalling router with cookie & scripting filtering built-in @ the hardware level), but that IS the bulk of it!)
ALL for security... & this post is especially for background to anyone on Win32 that DOES show an error in this test, as giorgosts on Linux did (to whom I am responding).
So, based on my test?
This has to be script related, because I did not see it @ all (no action from err #3 reported on Mr. Zalewski's page (and I did not think I would, because I keep scriptings of ALL kinds generally turned off 99.999% of the time in my webbrowsers on the public internet @ least)).
Good news!
(Above all - Thanks for your response & data)...
I would write more, but it is VERY late here, & time for shuteye!
APK -
Man: NEED COFFEE this a.m. (editing in correction)
EDIT REQUIRED OF MY LAST POST: I forgot to post the download url above (sorry) so it is now below here upon edit!
That is, should you be interested in trying my program, as an example of an app from the freeware world that is SMP/HT/MultiCore ready (this is not just present in commercial apps & why I post it)!
My bad, lol: I went to the Dicky Betts (of the Allman bros. band) show last night (sat.) w/ my friends, got in late, & had my share of brews + as my subject line states, I need a cup of coffee today bigtime!
(Ah, summertime fun! LOL, & no I do not drink brews when I code, haha, before anybody takes advantage of that 'confession' of mine here to bust my balls w/ it!).
Anyhow/anyways:
DOWNLOAD LINKAGE URL!
APK Registry Cleaning Engine 2002++ SR-7:
http://www.techpowerup.com/downloads/389/foowhatev ermakesgooglehappy.html
It is multithread designed (mostly coarse design, w/ SOME fine-grained multithread design), safest & most thorough registry cleaning program there is!
(In that it does not expose CLSID's of ActiveX/OLEServers for the safety, in the shipping model I put out for end-users there. I say this, because many other registry cleaners do, & if you blow those CLSID registrations (because this happens in some reg cleaners) & things in your OS & programs work, you know the reasons why - my personal model has a tab in it that allows this, but I do not ship that model to users, because it is dangerous, & the entire cascading CLSID model is why I don't ship it to users, because even not all coders understand this well unless they have done COM/DCOM type work before)!
It was proven so in tests against most ALL competitors in fact (see the download pages) by users with their OWN registry data unaltered (by test rigging .reg file insertions as Juoni Vuorio had done trying to fool users in the past)!
It also offers REALTIME, HIGH, NORMAL, & LOW cpu priority control over itself built right into it for working potentially faster (realtime (not for single cpu rigs), or high) OR less obtrusively in the background while animated trayicon minimized (low).
Enjoy it if you try it - & it is an example of smp/ht/multicore ready apps, & it has been in existence since 1997 & has not required a major rewrite since then, & yet runs safely across ALL Win32 OS models from Win9x/NT/2000/XP/Server 2003, & yes, even VISTA today!
APK
P.S.=> Moderators: If you wish to mod me down for 'hawking' my app here, go ahead should you feel it is trolling & necessary to do, on your parts!
(I could care less if you do so, because mod up/down points are not the point of this: The point is to instead show these guys that even in the freeware/shareware world for Win32 That multithread designed apps exist & have for a decade OR more out there, & they ARE smp/ht/multicore ready, if designed properly, per my last post above & what it outlined to the readers here, especially the one I responded to)... apk