Re: Full Disclosure of Security Vulnerabilities




I have the same situation some time ago. Somehow, the way and when we can
disclose the vulnerability depend on your agreement between you and your
client. On the right hand, as a security professional you should push the
software maker to also consider other client that may affected this
vulnerability as well. How their other customer should address this
vulnerability without disclosing, ... etc, so on.

Cheers,
Arif Jatmoko
InfoSec Officer - Coca-Cola Bottling Indonesia


|-----------------------------+-------------------------------------------|
|jfvanmeter@xxxxxxxxxxx | |
|Sent by: | |
|listbounce@xxxxxxxxxxxxxxxxx | To|
| | pen-test@securityfoc|
|11/01/2007 03:21 AM | us.com |
| | cc|
| | |
| | Subject|
| | Full Disclosure of |
| | Security |
| | Vulnerabilities |
| | |
| | |
| | |
| | |
| | |
| | |
|-----------------------------+-------------------------------------------|







Hello Everyone, I would llike to get your thoughts on Full Disclosure of
Security Vulnerabilities . About 3 weeks ago during a per-test of a
software suite for a client of myine, I found a directory traversal in a
software suite that my client has installed on thousands of workstation.

I send screen shots and a packet capture to the vendor and they were able
to to recreate the exploit.

my cleint doesn't want to go public with it because of the thousands of
workstations and servers that its installed on. I also don't believe the
vendor will go public with it, what would you all do?

Best Regards --John

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



_______________________________________________________________________________
Visit us at www.coca-colabottling.co.id

CAUTION:
This message may contain privileged and confidential information intended only for the use of the addressee named above. If you are not the intended recipient of this message, you are hereby notified that any use, dissemination,distribution, or reproduction of this message is prohibited. If you have received this message in error, please notify Coca-Cola Bottling Indonesia immediately. Any views expressed in this message are those of the individual sender and may not necessarily reflect the views of Coca-Cola Bottling Indonesia.


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Top 5 Common Mistakes
in Securing Web Applications
Find out now! Get Webinar Recording and PPT Slides

www.cenzic.com/landing/securityfocus/hackinar
------------------------------------------------------------------------



Relevant Pages

  • [Full-disclosure] RE: [NT] Microsoft Multiple E-Mail Client Address Spoofing Vulnerability
    ... As a security professional working for a Corporate Office the "Multiple ... E-Mail Client Address Vulnerability" (please see original advisory attached ... Outlook 2003 and Exchange 2003 as far as I could tell. ...
    (Full-Disclosure)
  • [NEWS] Cisco VPN 5000 Client Multiple Vulnerabilities
    ... Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) ... 5000 Client software. ... These vulnerabilities are documented as Cisco bug ID ... CSCdx17109 - MAC OS VPN 5000 Client password vulnerability ...
    (Securiteam)
  • [NT] Multiple Vulnerabilities in Mirabilis ICQ Client
    ... The ICQ client offers other client services, ... This vulnerability can be successfully exploited by an attacker ... ICQ Features on Demand spoofing attack: ...
    (Securiteam)
  • RE: PT Activity duration/time
    ... figure out the workaround or log it and give the client the patch notes. ... Vulnerability Assessment ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
    (Pen-Test)
  • RE: Re: secure client-side platform
    ... A - there is an exploitable vulnerability (in the remote-code-execution ... server by e.g. DNS, ARP, or routing protocol attacks somewhere upstream. ... What about client software vulnerabilities? ... > how to have a secure client-side platform for secret communication? ...
    (Bugtraq)