Re: [Full-Disclosure] Vendor non-acknowledgement

From: Nicob (nicob_at_nicob.net)
Date: 09/30/03

  • Next message: Keith W. McCammon: "Re: [Full-Disclosure] More on Dan Geer"
    To: full-disclosure@lists.netsys.com
    Date: 30 Sep 2003 18:47:15 +0200
    
    

    On Tue, 2003-09-30 at 16:37, Kent A wrote:
    > Do most vendors acknowledge security professionals that
    > bring vulnerabilities to them?

    Yes, that's the Usual Way.

    -- 
    Nicob <nicob@nicob.net>
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Keith W. McCammon: "Re: [Full-Disclosure] More on Dan Geer"

    Relevant Pages

    • Re: [Full-Disclosure] Vendor non-acknowledgement
      ... > based upon my notifications to them. ... Do most vendors acknowledge ... > security professionals that bring vulnerabilities to them? ...
      (Full-Disclosure)
    • Re: Towards a responsible vulnerability process
      ... To believe that vendors all behave the ... Microsoft has run the train off the tracks many times in the past. ... Getting a fix is ... security vulnerabilities, vulnerabilities that can be widely exploited, and ...
      (NT-Bugtraq)
    • RE: [Full-disclosure] Our Industry Is Seriously Ethics Impaired
      ... >The company is planning to reward security researchers who reveal ... >information on newly discovered vulnerabilities. ... >3Com will notify affected vendors of security flaws so they can ... >other security vendors prior to public disclosure. ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Our Industry Is Seriously Ethics Impaired
      ... > The company is planning to reward security researchers who reveal ... > information on newly discovered vulnerabilities. ... > 3Com will notify affected vendors of security flaws so they can ... > other security vendors prior to public disclosure. ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] Test your windows OS
      ... > These are not vulnerabilities in itself: you cannot gain access or elevate priviledges but I just wanted to let you know that these programmers did a sloppy job. ... Although most vendors had improved to where ... testing applications running on Windows/NT. ... Given valid random mouse ...
      (Full-Disclosure)