Re: [Full-Disclosure] Vendor non-acknowledgement

From: Giovanni Bobbio (giovanni_at_communicationvalley.it)
Date: 09/30/03

  • Next message: Ron DuFresne: "RE: [inbox] Re: [Full-Disclosure] CyberInsecurity: The cost of Mo nopoly"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 30 Sep 2003 19:02:20 +0200
    
    

    On Tuesday 30 September 2003 18:07, Florian Weimer wrote:
    > On Tue, Sep 30, 2003 at 09:37:53AM -0500, Kent A wrote:
    > > Novell recently put out security release
    > > (http://support.novell.com/cgi-bin/search/searchtid.cgi?/10087316.htm)
    > > based upon my notifications to them. Do most vendors acknowledge
    > > security professionals that bring vulnerabilities to them?
    >
    > I can understand that a company such as Novell doesn't want to credit
    > "Kent A <bowulf@myrealbox.com>" with the discovery of a software
    > vulnerability.

    I don't understand it, could you explain your rationale?
    And we don't really know whether he identified himself as Kent A or Mickey
    Mouse or...

    Giovanni

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Ron DuFresne: "RE: [inbox] Re: [Full-Disclosure] CyberInsecurity: The cost of Mo nopoly"

    Relevant Pages

    • NOVL-2002-FAQ - Novell Security Alerts Facts Sheet
      ... Vendor Name: Novell, Inc. ... In light of increased customer interest in Internet-related security ... Novell is taking steps to better inform our customers and partners ... vulnerabilities in our products along with recommended corrective ...
      (Bugtraq)
    • [Full-Disclosure] Disclosure Debate FW: [ISN] When to Shed Light
      ... Information security, in particular, cannot exist. ... full disclosure results in FEWER hands at work in this process, ... Microsoft because of how dependent publishers are on access to beta software ... > I think actively seeking vulnerabilities is just plain destructive. ...
      (Full-Disclosure)
    • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
      ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
      (microsoft.public.security)
    • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
      ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
      (microsoft.public.inetserver.iis.security)
    • Re: Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
      ... I do agree that when a security consultant finds potential security ... responsibly and provide details of the vulnerabilities discovered to ... what happened on the last 6 months between us and Microsoft: ... Microsoft's solution for the IIS 5.0 FPE2002 vulnerability we ...
      (microsoft.public.dotnet.framework.aspnet.security)