Home > Ask the Security Experts > Questions & Answers > Comparing Microsoft IIS and Apache Web servers
Ask The Security Expert: Questions & Answers
EMAIL THIS

Comparing Microsoft IIS and Apache Web servers

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site
>
QUESTION POSED ON: 14 October 2003
Would you please give me a comparison of Microsoft IIS and open source Apache Web servers for the following security issues?

  • Number of security breaches
  • Time to provide a fix or patch for problems
  • Targeting by the hacker community

  • >
    The best compilation of such materials that I've seen is the work by Ron Ritchey. Hiswork is about two years old, but it still holds some valuable lessons. To summarize his findings, both Web servers have had major flaws. The number of IIS breaches has been higher in the past, and the time to release fixes was longer.

    More recently, Microsoft has worked to close this gap. I haven't seen a detailed survey of the issue since Ritchey's survey, but in my experience, Microsoft is meeting some success in IIS itself. (However, major problems, such as WebDAV from May 2003, continue to be discovered.)

    The hacker community has taken a keen interest in exploiting IIS, given its widespread use, history of flaws and Microsoft origin. While both Apache and IIS exploit research is ongoing, it appears that the number of people attacking IIS is higher.

    So, how should you decide whether to go with Apache or IIS? I advise that you focus on the one where your team has the most system administration expertise. Sure, Apache may be theoretically less vulnerable than IIS. But, if your team cannot administer an Apache box, you are hosed. A well-maintained IIS box is certainly more secure than a poorly maintained Apache box. Likewise, if your team has solid Apache expertise, go with that.


    For more info on this topic, visit these SearchSecurity.com resources:
  • Best Web Links: Web servers
  • Web Security Tip: Keep Apache patched
  • The Information Architect: Microsoft pushes security in IIS 6.0


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts