Internet Information Server - don't do it

Software too vulnerable to attack, warn analysts

Written by James Middleton

Analysts are advising against using Microsoft's Internet Information Server (IIS) because of its multitude of vulnerabilities that viruses like Nimda and Code Red exploit.

The Gartner Group has advised enterprises that had not yet made web server decisions to "weigh security heavily and to evaluate other web server software offerings" rather than opting straight out for IIS.

And for those which have already opted for IIS and have been hit by Code Red or Nimda, Gartner suggests "immediately investigating alternatives to IIS, including moving web applications to web server software from other vendors, such as iPlanet and Apache".

John Pescatore, information security strategies analyst at Gartner, said the track record of IIS should prompt enterprises with web applications to rethink their choices and "start investigating less vulnerable web server products".

He explained that, while platforms such as Apache or iPlanet have also required security patches in the past, they "have much better security records than IIS and are not under active attack by the vast number of virus and worm writers".

Pescatore said that IIS, and most likely Microsoft's .Net service too, would continue to be under attack until its code base is completely rewritten - something he doesn't envisage happening until 2003.

"For Microsoft's vision of .Net and web services to succeed, Windows XP will have to be significantly more secure than Windows 2000 has proven to be; otherwise, Microsoft risks losing some enterprise business to more secure implementations of web services," he said.

Pescatore maintained that the same old buffer overflow problems appearing in beta Windows XP code raise doubts over the effectiveness of Microsoft's security assurance tools.

Gartner's research also concluded that, based on how easy it is to attack IIS web servers, "using internet-exposed IIS web servers securely has a high cost of ownership".

For users already on the IIS path, Gartner emphasises that all enterprises should, as a minimum, go through the security checklist and install all patches.

But the analyst also warned that "the constant need to deploy these patches continues to increase the total cost of ownership of IIS web servers and always leaves periods of vulnerability", suggesting that users will always be on their toes, and never quite watertight.

Gartner's reports can be found here and here.

Tags:

Further reading

Honest Bill says Microsoft is trustworthy

Availability, security and privacy the new priorities, apparently   More...

Sun cuts prices to lure Microsoft users

Move follows Gartner's advice to dump IIS   More...

80,000 Microsoft servers 'disappear'

Code Red and Nimda cause 150,000 IIS-based sites to fall off the web   More...

Killer virus ravages internet

Latest worm has the worst elements of Sir Cam and Code Red   More...

Related articles

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

Warning on web 'super worm'

XSS database could cause major problems   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

08 Jul 2008

3.67 MBSafe browsing, voice recognition and cyber-criminals More...

07 Jul 2008

2.76 MBLaptops on holiday, gaming in Vietnam and 'unbreakable' encryption More...

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Firefox

Firefox users shown to be safer

Internet Explorer users the worst of the bunch   More...

Internet Corporation for Assigned Names and Numbers

Icann downplays recent site hacks

Redirects were 'limited', says organisation   More...

Advertisement

DNA

Boffins build artificial DNA

Could be used in the ultimate computer   More...

Microsoft

Microsoft outlines appeal against EU fine

Two sides back in court   More...

Advertisement