Re: information disclosure

From: Barry Margolin (barmar_at_alum.mit.edu)
Date: 03/24/05


Date: Wed, 23 Mar 2005 20:44:20 -0500

In article <Xns962249AC87178WQAHBGMXSZHVspammote@130.39.198.139>,
 bz <bz+csm@ch100-5.chem.lsu.edu> wrote:

> joshandlinds@gmail.com wrote in news:1111554686.962430.22570
> @l41g2000cwc.googlegroups.com:
>
> > I found a HUGE security hole on my college website about a year ago and
> > it still hasn't been fixed. It shows SSNs, Names, birthdates, address,
> > phone etc... How dow I let peole know without getting in trouble myself?
>
> I suggest you call the admin in charge of the web site and tell him/her
> about the problem.

His phrase "still hasn't been fixed" suggested to me that the admins
know about it. I.e. I assumed he told them about it a year ago, they
haven't done anything about it, and now he wants to know how to
publicize it more widely in order to get them to fix it, but without
getting into trouble for doing so.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***


Relevant Pages

  • Re: Understanding /root, /usr, /var and so on
    ... big security hole to me. ... As the admin, the admin should be responsible for that, with those configs locked down for normal users. ... that exact reason, seperation of responsibilities. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • Re: Understanding /root, /usr, /var and so on
    ... Not everyone has the privilege of owning their own admin. ... to ifconfig and its ilk sure sounds like a big security hole to me. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • information disclosure
    ... I found a HUGE security hole on my college website about a year ago and ... It shows SSNs, Names, birthdates, address, ...
    (comp.security.misc)
  • Re: Windows 2000 non-admin account issue
    ... This avoids the ... security hole of having to hand out the admin password. ... By any local account ... ...
    (alt.internet.wireless)

Quantcast