[Full-Disclosure] What is better anyway?
From: Sir Mordred (mordred_at_s-mail.com)
To: firstname.lastname@example.org Date: Mon, 12 May 2003 14:31:11 +0000
Well, three security notices have been released,
which exposed holes in several hacking websites and several security
Everyone who read them, can actually see that is the real state of web app
Everyone who read them, can see that vulnerabilities are truly dumb and
freely available for everyone,
for everyone who ever bothers to change url a bit, or to change the url
Who guesses nothing more, that /admin/, /test/, and test.php...
Who is kewl enough to add single quotes/commas...
Who even dont wanna to bother about hiding himself..
Interested what results i've got from this?
1) content of http://mslabs.iwebland.com has been deleted, to hell with
what you expect from free hosting? so i decided to leave an idea about
website until the time
i can afford dedicated machine...
2) some people begin to investigation of "hack attacks",
which has been no more then just simple and basic security testing...
3) for some of the people the notices have been old news
And again, this question araises...
What is better?
To see your website exposed in a security notice, or
to leave it in the state it is, owned by some few people (including me of
course), who can deface it
anytime they want, who can access you customers database...?
If you choose the first, then should the man who found and published it to
be tracked down and sued?
What if he notified you before publishing the details? Does it matter?
Or you should thank that man?
Any feedback will be appreciated.
Also, i would like to hear some words from the people who actually have
been exposed in the notices.
For now i have a feeling that i should stop "security noticing" forever...
// Sir Mordred
This letter has been delivered unencrypted. We'd like to remind you that
the full protection of e-mail correspondence is provided by S-mail
encryption mechanisms if only both, Sender and Recipient use S-mail.
Register at S-mail.com: http://www.s-mail.com
Full-Disclosure - We believe in it.