Yes, you're correct and Apache is no better than IIS is in the wrong hands is the bottom line. And part of what makes IIS in secure is that WEB programmers don't know how to write secure WEB applications that face the Internet and that was made very clear to me in some recent training how inexperienced WEB developers leave or are unaware of the gaping security holes in the application.
Duane :)