Or don't run programs that are the most insecure out of the one's out there,
and don't run a services that require you to need to use firewalls, IDS, and
anti-virus tools.

Not that these are bad things, they certainly can improve system security,
depending on the platform and what you run, but are not needed if you choose
the right software in the first place.
--
Regards,
Tim Greer  [EMAIL PROTECTED]
Server administration, security, programming, consulting.


----- Original Message -----
From: "Dan Bartley" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, July 03, 2003 12:25 PM
Subject: RE: Ten least secure programs



That link is just a page listing possible IE holes, not showing how
Mozilla has none. Mozilla has had its fair share too. So has Opera. In
the latter a few glaring very old holes. I think the "browsers in
general" is the closest. It is the nature of consumer demand. Meet what
people want and you have new problems.

Browser related functions is also the single biggest source of problems
in the enhanced email clients security problems.

So if you really want to catch the top ten, just say no more www related
activity or no applications with www related functions enabled.

Of course that is not really feasible in most current work environments,
so probably better consider what tools are really needed and you have
the resources to properly administer and configure, take IDS and
anti-virus steps, then ban the rest.

Best Regards,

Dan Bartley

-----Original Message-----
From: Steve Bremer [mailto:[EMAIL PROTECTED]
Sent: Wednesday, July 02, 2003 13:08
To: [EMAIL PROTECTED]
Subject: Re: Ten least secure programs

>> IE doesn't seem to have that many more vulnerabilities than
netscape
> so I think it's just browsers in general.

I don't think that's necessarily true for Mozilla.  See
http://pivx.com/larholm/unpatched/

A properly configured IE may be fairly safe, but it a lot of the
security  bugs tend to bypass IE's built-in security features.



---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.

Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.

Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------

Reply via email to