On Tue, 4 Mar 2003 13:07:39 -0000, "Robert Peffers" <
[email protected]> wrote:
>Let's lay that old myth to rest once and for all. The main motives of anyone going to the bother of
>designing any kind of malicious programme is one of two main things. They stand to make a profit
>from doing so by also designing protective software, making a name for themselves, or they hold a
>grudge, real or imagined, against the computer using public.
Or they do it for intellectual curiosity "because they can" - this is a strong motive among script
kiddies, reportedly.
>In both cases they rely on surprise and hitting the most popular stuff so will attack when not
>expected. If you use OE you already expect the attacks and take precautions. If you do not use OE,
>and think yourself safe, beware.
Is the wrong answer. IIS has a very small share of the worldwide http server market, but a
disproportionately large share of the hacked / cracked sites. The software has to be common *and*
easily exploitable. I remember one virus on the Macintosh, which was easily prevented with a simple
INIT. I have never seen a Linux virus. There is a huge body of programmers deeply committed to
Microsoft, many of whom hate Linux with a passion. They still haven't managed to come up with a
virus. Most exploits affecting open source software are established by the developer community,
disseminated immediately and patched rapidly - almost always before the baddies have managed to
exploit them. Microsoft get in a snit if anybody even mentions the existence of a security hole
before they've had a chance to patch it, which can take months.
Face it, Microsoft software is insecure by default. Some of it can be made secure, some can't, but
the root of the problem is that Microsoft don't take security half seriously enough at the design
stage (a fact which Bill Gates himself acknowledged last year). It is also bloated, and obscure. You
can't change some of the things you need to without hacking the registry, and Microsoft officially
don't support that (even when it's the only way and you're following their instructions). And you
can't load a server without the GUI! How **** is that?
Right, that's me off Usenet until Easter.
Guy
===
** WARNING ** This posting may contain traces of irony.
http://www.chapmancentral.com (BT ADSL and
dynamic DNS permitting)
NOTE: BT Openworld have now blocked port 25 (without notice), so old mail addresses may no longer
work. Apologies.