Netcraft November now out

The new Netcraft is out for November. Pretty much the same, no big moves. IIS dropped 2% or so (which is not much considering most of that is attributed to one major install, the Gartner report and every day security issues dont appear to be making much of a difference.)

Netcraft points out a potential "JSP" vulnerability with certain app servers using the "Sun reference implementation of the Java Servlet Development Kit (JSDK 2.0)." The vulnerable systems allow session IDs that are predictable (base32 encoded in a known manner) and include "Java Web Server (JWS) from V1.1, IBM WebSphere and ATG Dynamo e-Business Platform." This is all a little confusing since a JSP IS a servlet and servlets arent mentioned, but you get the idea from the advisory.

For more on the survey and the advisory check the Netcraft link ---------------->   http://www.netcraft.com/survey/