RE: Publishing Findings on Commercial Applications
- From: "Jezebel Ali" <jezebel_ali@xxxxxxxx>
- Date: Wed, 14 Jun 2006 11:04:59 +0400
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Dear Friend Ralph Forsythe,
I appreciate very much your response. It make sense to me and
after reading lot of mail that I will take internal path to client
& vendor. It is true I paid to do penetration test from client. I
will try convince client to make push so that vendor will patch
product on whole rather than only client. I argue that it is good
for industry if this direction is taken. Maybe client will appear
benevolent also in industry.
Thank you once again friends for reading and taking valuable time
to respond.
Kind Regards,
Jez
On Wed, 14 Jun 2006 02:58:17 +0400 Ralph Forsythe
<rforsythe@xxxxxxxxxxxx> wrote:
Another question to answer -- Would disclosing the information-----BEGIN PGP SIGNATURE-----
discovered
put your client at potential risk?
I'm not sure of the legal ramifications of disclosing a flaw you
found
(even if identifiable information were removed) during a
contracted
pen-test, versus one you found in your own free time. If the
client then
gets violated through your discovery by chance just because of
what they
do, it's conceivable that they could have a case against you.
Yeah I know
people disclose vulnerabilities daily, but generally those people
aren't
being paid by potential targets to find the holes either.
In a roundabout way, you'd be telling the world "here's how to
hack my
client" even without disclosing their name, if that software
package is as
pervasive as you say it is. I know if I were a bank and this
happened to
me, I'd have my legal counsel on the phone in about 3.2 seconds,
if even
to find out I had no case (but I'd still be looking very hard at
it).
If you are 100% sure you have nothing contractual barring it, I'd
still
consult a lawyer to make sure you aren't setting yourself up for a
bad
time. Ethically (and perhaps legally as well) I think contacting
the
vendor first is probably the best path to take. That doesn't mean
you
can't disclose it publically, but you may come to an agreement on
delaying
that email while they prepare a patch. You'll also be more of a
fan to
those banks' customers, who will appreciate the immediate response
rather
than waiting an indeterminate amount of time during which their
accounts
could be vulnerable to who knows what.
- Ralph
On Wed, 14 Jun 2006, Sahir Hidayatullah wrote:
Might be a better idea to contact the vendor first.flaws.
These days you can get into all sorts of trouble for revealing
isn't it ? :)
Besides, it's probably more ethical to work with them first
site
You could also follow RFP's disclosure policy:
http://www.wiretrip.net/rfp/policy.html
Regards,
--S.
-----Original Message-----
From: Jezebel Ali [mailto:jezebel_ali@xxxxxxxx]
Sent: Wednesday, June 14, 2006 1:00 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Publishing Findings on Commercial Applications
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Greetings Brother and Sister List Members,
I have question: If I performing Penetration Test on customer
and this customer has a commercial application which is notto
publicly available for download or purchase, do I have a right
publish finding of this application to the public withoutand
mentioning customer name?
This application widely used by banking and financial industry
not always available to anyone for testing.https://www.hushtools.com/verify
Kind regards,
Jez
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at
Version: Hush 2.5wpwEAQECAAYFAkSPEjEACgkQC68hZJzwc9hmzQP/XdSnsXhREbRPUQsCyDrabyaRQb7
A
h2c617zR73xrSAlyXROxP6tJhxfLKiNkNKRb6yfNEJMcYQyr+nduJDoG/9FIix1hVns
2
WewlBCrufnT3ZNcLa7+KNeHYpMkhHPcAop9NjUJDgUILQwbJLzv7cWPK5wcz74eYwCk
F
5Q4IqlE=no account
=jFJM
-----END PGP SIGNATURE-----
Concerned about your privacy? Instantly send FREE secure email,
required-----------
http://www.hushmail.com/send?l=480
Get the best prices on SSL certificates from Hushmail
https://www.hushssl.com?l=485
-----------------------------------------------------------------
--the Analyst's
This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win
Choice Award from eWeek. As attacks through web applicationscontinue to
rise,Cenzic has
you need to proactively protect your applications from hackers.
thepenetration
most comprehensive solutions to meet your application security
testing and vulnerability management needs. You have an optionto go with a
managed service (Cenzic ClickToSecure) or an enterprise softwareservice can
(Cenzic Hailstorm). Download FREE whitepaper on how a managed
help you: http://www.cenzic.com/news_events/wpappsec.phpconfirm your
And, now for a limited time we can do a FREE audit for you to
results from other product. Contact us at request@xxxxxxxxxx fordetails.
----------------------------------------------------------------------------
---------------
-----------------------------------------------------------------
This List Sponsored by: Cenzicthe Analyst's
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win
Choice Award from eWeek. As attacks through web applicationscontinue to rise,
you need to proactively protect your applications from hackers.Cenzic has the
most comprehensive solutions to meet your application securitypenetration
testing and vulnerability management needs. You have an optionto go with a
managed service (Cenzic ClickToSecure) or an enterprise softwareservice can
(Cenzic Hailstorm). Download FREE whitepaper on how a managed
help you: http://www.cenzic.com/news_events/wpappsec.phpconfirm your
And, now for a limited time we can do a FREE audit for you to
results from other product. Contact us at request@xxxxxxxxxx fordetails.
------------------------------------------------------------------------------
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.5
wpwEAQECAAYFAkSPtRsACgkQC68hZJzwc9gNvwP+M5+YSyLHYO2AcliYpyQD/JkUhc63
NHtHxNne6+53wyUu2MiujYUBtIldo0FTb+7B3ooonzdSaxHFKNkknrpy0DG9SHM/D8QJ
5M2xGRaNK1WzoDuRpGGa68gYIGeQbUr+zV2lIg3lFawOzUDbQdolNAxiyMZz37ay17VQ
L2JHueM=
=VRKI
-----END PGP SIGNATURE-----
Concerned about your privacy? Instantly send FREE secure email, no account required
http://www.hushmail.com/send?l=480
Get the best prices on SSL certificates from Hushmail
https://www.hushssl.com?l=485
------------------------------------------------------------------------------
This List Sponsored by: Cenzic
Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx for details.
------------------------------------------------------------------------------
- Prev by Date: RE: firewall auditing/testing
- Next by Date: RE: firewall auditing/testing
- Previous by thread: Re: Publishing Findings on Commercial Applications
- Next by thread: Black Hat Speakers + 2005 Content on-line
- Index(es):
Relevant Pages
|
Loading