This page explains details about the security of the AOLServer web server. For an overview of the general security strategy please check here.
AOLServer (the web- and application server of ]project-open[) is not a commonly used web server such as Apache or the Microsoft IIS. This means that it is relatively uninteresting to potential hackers. Internet viruses or worms would not find sufficient hosts to replicate.
Hackers prefer popular web servers because normal Internet users are not as disciplined with security patches and they are not that skilled with configuration and other security precautions.
"AOLserver is the backbone of the largest
and
busiest production environments in the world"
www.aolserver.com
AOLServer is being used by AOL as the basis of their worlwide infrastructure. AOLServer used to be property of AOL after they bought the system from a small software company "Navi Soft". However, AOL understood the advantage of the open-source model and released the code under the GNU Public License for the use of third parties.
AOLServer is supported by AOL because vulnerabilities in the system would pose a serious thread to AOL. OpenACS and ]project-open[ are benefitting heavily from this support. Both organization are greatful for this service and are actively involved in debugging, extending and maintenance of the system.