Vulnerability Development mailing list archives

Re: defacement stats


From: "Zow" Terry Brugger <zow () llnl gov>
Date: Tue, 22 Apr 2003 13:32:35 -0700

Is there any site on the web that has defacement statistics based on the
application software. Alldas had stats based on OS. Safemode sometimes
(once?) put out stats for both OS as well as application software. 

      I'm not aware of any, and I honestly don't see why there should
be.  Apart from Microsoft's worm-friendly[*] IIS web server, very few web
servers are even tangentially to blame for the breach itself. 

I didn't take the question to be in reference to the web server itself, but 
rather any applications that might be running on top of it, like PHP Nuke, 
Zope, Slashcode, or any other of the numerous content management or comment 
systems that run on top of the HTTP server. At least, I think that's a more 
interesting question than what web server was running at the defaced site.

Terry

use Standard::Disclaimer;



Current thread: