A Guide to Building Secure Web Applications
some-guy writes "The Open Web Application Security Project has released
A Guide to Building Secure Web Applications, Version 1.1
"While this document doesn't provide a silver bullet to cure all the ills, we hope it goes a
long way in taking the first step towards helping people understand the inherent problems
in web applications and build more secure web applications and Web Services in the
future...""
Easy... Don't use IIS as your server.
Why else?
Security by obscurity.
Just because we don't agree with the concept doesn't mean that it doesn't exist.
2) ???
3) Secure!