Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register
WINDOW MANAGER  

There's life left in IIS

New tools mean reports of Internet Information Server's death have been greatly exaggerated

By Brian Livingston
January 17, 2003
 

INTERNET Information Server (IIS) don't get no respect.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

Try Sun servers, workstations and storage products free for 60-days.

Sponsored by Sun Microsystems

Microsoft's Web server software suffered a heavy blow to its reputation when the Code Red and Nimda worms exploited weaknesses in millions of IIS installations in the summer of 2001. Wags said the IIS acronym really stood for "It Isn't Secure." Research group Gartner published a widely reported recommendation in September of that year, saying users should "immediately investigate alternatives to IIS." (See www3.gartner.com/resources/101000/101034/101034.pdf .)

Perhaps as a result, Microsoft's offering has shown a big decline in the closely followed Netcraft survey of Web domains. IIS peaked at a 35 percent market share in March 2002, then declined to under 28 percent by the end of the year. Meanwhile, Apache servers -- which always outnumbered IIS on a per-domain basis -- are running almost 63 percent of the sites in the world and growing (www.netcraft.com/survey ).

The Netcraft snapshot doesn't tell the whole story, however. "It's kind of misleading," says Chris Neppes, director of sales and marketing at Port80 Software, because Apache servers are more likely to host numerous small sites -- each of which counts as one server in the survey.

Port80 has just completed its own study of the Web server software used by large companies in the Fortune 1000. The figures show that, of 970 corporations with identifiable Web sites, 54 percent are using IIS. The number is 21 percent for Netscape Enterprise, 18 percent for Apache, and 7 percent for other or unknown software. (The study should be available by the time you read this at www.port80software.com/servermask/fortune1000webservers .)

Port80 sells add-on software that makes IIS more reliable and therefore more competitive. The most notable is ServerMask, which is based on a principal caller server anonymization. In a nutshell, ServerMask stops IIS from announcing its identity to the majority of malicious hackers or anyone else. This is important because new security weaknesses that become known usually affect specific versions of a piece of software. Hackers who scan the Web to build lists of vulnerable machines are likely to target someone else if your server keeps mum about itself.

The third edition of ServerMask -- a significant upgrade that hasn't been announced yet -- will gear up even more to deal with the latest threats. Script-kiddie tools, for example, can now identify servers by their distinctive Internet Protocol settings, such as TTL (Time to Live).

The new add-on will analyze your traffic and recommend a better range of settings than the defaults, according to Joe Lima, Port80's COO.

ServerMask may double in price in February, Neppes says, but purchasers of the current edition, at $49.95 per server, will get a free upgrade.

Port80's anonymization software may make surveys like Netcraft's less accurate. But that's no reason for your company to become a statistic.





 


 
Brian Livingston is co-author of 10 Windows Secrets books. Send tips to brian@secretspro.com. Subscribe to Window Manager and E-Business Secrets at www.iwsubscribe.com/newsletters.
 

TOP NEWS:


»  Software piracy hurts the open-source community too
Many nations are beginning to see stolen proprietary software as a lost opportunity for open source software, whose development can encourage innovation and job growth

»  Intel readies slew of embedded chips based on Atom core
Intel is trying to increase performance and drop power consumption in more than 15 system-on-chips that use the Atom core

»  Microsoft surprise reorganization aimed at online woes
Microsoft's online troubles hint at larger vulnerability; the company is facing challenges in areas that have been a lock for many years

»  Attack code released for DNS bug
Security experts warn that this attack code may give cybercriminals a way to launch virtually undetectable phishing attacks

»  Parts of San Francisco network still locked out
Administrators are still locked out of the city's VoIP system and LANs within the Sheriff's Department and the Recreation & Park Department

»  Intel says Moblin update coming soon
Open-source effort set for mobile Linux should have an alpha-level release in a few weeks




Solutions to the Toughest IT Challenges in Remote Offices
Though small in size, remote offices face many of the same IT challenges as larger central offices. This Webcast zeroes in on the top line challenges to deliver information that can provide immediate benefits to your business. Sponsor: AMD and Dell

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist