NEWS A Microsoft security expert claims system administrators do not do enough to shore up IIS web servers from security threats, with the result that the software looks more vulnerable than it actually is. Ian Hellen, principal security consultant at Microsoft UK, said that a large percentage of system administrators' approach to updating patches on server software is too laidback, with the result that the company's reputation for server security has been distorted. Analyst house Gartner issued a controversial warning two weeks ago to companies using Microsoft's web server software, recommending them to seek alternatives to Internet Information Server (IIS) because of the serious security risks. However, Microsoft has defended its corner and said its software is as secure as its competitors, if not more so. Hellen said the vulnerabilities of IIS are distorted because of a large user base, and because the easy installation option does not invoke the highest security settings available in the software. He said: "When IIS gets hit by viruses the figures look a lot worse than they are because 50 per cent of the world's servers have IIS... Also there is always a risk of human error as lot of people just get the software up and running quickly and then just forget all about it." Hellen added: "There is a certain sys admin culture which might make the patches issued ignored." Gartner recommended that users consider products from vendors such as iPlanet, and the open source Apache server software instead. However, Hellen insisted that competing products are no better than IIS. "There were more patches issued for Apache servers last year than for IIS," he claimed. Gartner asserted that one reason the security risks in using IIS are so high is because Microsoft doesn't react fast enough to vulnerabilities and supply security patches in time. Microsoft has responded by changing the default security settings on the latest versions of IIS, and by making it easier for sys admins to find patches on its website.
Microsoft blames laidback sys admins for IIS breaches
But software giant says IIS is safer than the rest...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




