Re: [Full-Disclosure] Re: Oracle Security Contact

From: Chris Wysopal (weld@vulnwatch.org)
Date: 11/06/02


Date: Wed, 6 Nov 2002 16:03:25 +0000 (GMT)
From: Chris Wysopal <weld@vulnwatch.org>
To: "Steven M. Christey" <coley@linus.mitre.org>


There is a list of vendor contacts maintained by VulnWatch to assist our
readers:

http://www.vulnwatch.org/links.html

There you will find product security email contacts and links to vendor
security bulletin archives.

Updates or new contact information welcome. Please mail
webmaster@vulnwatch.org.

-Chris

On Tue, 5 Nov 2002, Steven M. Christey wrote:

>
> On the full-disclosure list, low halo asked:
>
> >Could someone please give me the security contact address for Oracle
> >Corporation? It seems as though their marketing department's
> >"Unbreakable" slogan makes them think that its OK to bury their
> >security advisories & contact info deep within their site somewhere.
>
> It's not immediately obvious when navigating from the www.oracle.com
> home page, but it's listed at:
> http://otn.oracle.com/deploy/security/alerts.htm
>
> secalert_us@oracle.com
>



Relevant Pages

  • [NEWS] Wonderware SuiteLink Denial of Service Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vendor Information, Solutions and Workarounds ... Core sends the advisory draft to Wonderware support team. ...
    (Securiteam)
  • [Full-Disclosure] Security Industry Under Scrutiny: Part 3
    ... > varying degrees of 'faith' in the security industry. ... site admins and other whitehats. ... > architect would be notifying the software vendor alone... ... Full disclosure isn't so much a tool to get vunerability information ...
    (Full-Disclosure)
  • [NT] Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass (MS0
    ... Get your security news from a reliable source. ... Internet Explorer Zone Elevation Restrictions Bypass and Security Zone ... Vendor Information, Solutions and Workarounds: ... Core sends an advisory ...
    (Securiteam)
  • RE: Vendor wants remote control of our Servers and Workstations
    ... Of course the age-old problem with security is that ... Vendor has significant access to your internal ... this vendor uses the same method to support a number ... customer and makes significant changes ... ...
    (Security-Basics)
  • Security researchers organization
    ... of security researchers, plain and simple. ... better than the vendor itself. ... industry, telecommunications industry and banking industry has ( ... These are all common ideals we can agree and act upon, ...
    (NT-Bugtraq)