Vulnerability Development mailing list archives

Re: Notes Domino Server Platform for e-commerce?


From: wozz+exploit-dev () WOOKIE NET (Wozz)
Date: Thu, 10 Feb 2000 02:53:51 -0700


On Wed, Feb 09, 2000 at 09:10:27PM -0500, Derek Reynolds wrote:
Hello Marc,



Notes has been out much longer then Apache.  It's got at least 10
years on it. There have been 0 password issues to
date.  I can list at least 20 issues with Apache in the last year but
can't think of 2 for Domino.


According to the security focus vulnerability database

Apache: 2 (both of which had to do with leftover CGI's from NCSA)
Domino/Notes: 4

As my statement stands. I would deam Domino/Notes as secure.


Anyone who says something is "secure" is just gonna look silly when the next
bug comes out.  Nothing is secure, there will always be ways to exploit
software.  Me, I'd prefer something I can look at the source myself and make
sure is secure, rather than relying on a vendor, in who's interest it is to
keep me buying stuff.

Also your statement:
No, if you want a more robust webserver, try apache, I'm *positive* it was
audited far more than any webserver on the planet, WebSphere included.

Do you have any clue why Apache is named what it is?  It was named
Apache because there where so many problems with it "A PATCH" was created
so often they decided to call it A PAtCH E.  Also note that a web

Wrong.  It was named Apache because it was originally a collection of
patches folks had written for NCSA's server that several folks bundled
together.  Immediately after that first public release, when they saw how
popular it was, they started rebuilding it from scratch.  Everything after
Apache 0.8.8 was basically all new code.  Check on your stories before you
spin them.

server such as Apache alone is not truly a dedicated
EBusiness/Ecommerce based webserver. It requires many modules which
haven't been put to the test.  Apache alone is far from a good
transaction based Web Server.  That is where WebSphere accelerates.

We are talking about Ebusiness, Marc. Not marcs.homepage.com


Does your IBM VAR have you on a advertising-iv-drip?  You spout the party
line better than Pravda.  Take a look at netcraft.com and see just how many
sites are running Apache as opposed to those running Domino.  Domino
isn't even in the top 10.  WebSTAR on Mac's has a higher market share(.068%) than
Domino (.023%) when it comes to sites in Netcrafts database (9,950,491
sites).  Apache is #1 with 54%


Current thread: