Slashdot Mirror


Microsoft's IIS is Twice as Likely to Host Malware?

eldavojohn writes "According to Google, Microsoft's server software is at least twice as likely to host viruses or malware. The reason why? 'Google reports that IIS is likely used to distribute malware more often than Apache because many IIS installs are on pirated Windows versions which aren't configured to automatically download patches. (Even pirated Windows versions can automatically receive security fixes, however.) Our analysis demonstrates how important it is to keep web servers patched to the latest patch level,' Google notes."

4 of 163 comments (clear)

  1. Help me out by mingot · · Score: 4, Insightful

    Patches? Patches for what? Has IIS had any remotely exploitable holes since version 5? Or are these machines that get owned via some other method and then just happen to have IIS so it is used to serve the malware? So really, this has more to do with unpatched windows than IIS? Or am I missing something?

  2. No kidding /sarc by N3WBI3 · · Score: 3, Insightful

    The problem is anyone out there who can install windows services considers themselves a knowledgeable sys-admin. Sure there are technical reasons why LAMP tends to be more secure than IIS but more often than not it comes down to poor configuration (running unneeded services, poor network security, poor hardening standards), lazy maintenance (not checking logs, updating software), and a lack of understanding threats (not keeping up with cert).

    Linus once said of Gnome that when you design assuming you're users are idiots in the end thats all the users your going to have. Find an experienced competent admin who has cut his teeth in the real world and not in a MCSE bootcamp and you should be ok.

    --
  3. Newsflash! by DrEldarion · · Score: 4, Insightful

    Bad admins run bad servers!

    Wouldn't have expected that one.

  4. Re:49/49 by sqlrob · · Score: 4, Insightful

    The instances were evenly split, but since Apache is more common that IIS, you should see more Apache.