[thelist] Website Database Security

Ryan Finley RyanF at SonicFoundry.com
Thu May 3 15:38:15 CDT 2001


<<
The most documented tools are obviously the opensource ones, because any
hacker could look at the sources and figure out where's the hole. Thus more
attacks, more docs, imho better "hole fixes".
>>

Not sure if I quite agree here...

If the hole was obvious from the code, then the original programmer would
have fixed it in the first place!

I think that a better metric is:

The most USED tools have the most attacks, most docs, and imho better "hole
fixes".

Now IIS isn't exactly the most secure webserver...But with the number of
hackers beating on it every day, it eventually ends being very secure.  As
long as you keep up with the "hole fixes".

Just a thought...

	Ryan Finley
	President - SurveyMonkey.com (http://www.surveymonkey.com)




More information about the thelist mailing list