Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Raghu Chinthoju
I say, ... hey listen! your house entrance door latch isn't strong enough.. there are only 4 screws instead 16, which is the practice.. you have a risk of some one easily barging into your house For some reason you don't respond.. I publish it in the local news paper that .. Mr. X's door

RE: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Fielder, Kevin \(GE Consumer Finance\)
-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Websites vulnerabilities disclosure I say, ... hey listen! your house entrance door latch isn't strong enough.. there are only 4 screws instead 16, which is the practice.. you have a risk of some one easily barging into your house For some

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Peer Janssen
Raghu Chinthoju wrote: I say, ... hey listen! your house entrance door latch isn't strong enough.. there are only 4 screws instead 16, which is the practice.. you have a risk of some one easily barging into your house For some reason you don't respond.. I publish it in the local news paper

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Georgi Guninski
On Fri, Oct 07, 2005 at 09:57:02AM +0400, offtopic wrote: PS. About ethic. Ethics in money driven environments. Manipulation tool or reality? some romantic lawyer may have written a phd thesis on it. -- where do you want bill gates to go today?

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Valdis . Kletnieks
On Fri, 07 Oct 2005 14:38:34 +0530, Raghu Chinthoju said: I say, ... hey listen! your house entrance door latch isn't strong enough.. there are only 4 screws instead 16, which is the practice.. you have a risk of some one easily barging into your house For some reason you don't respond..

RE: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Adriel Desautels
] On - -- Behalf Of [EMAIL PROTECTED] - -- Sent: Friday, October 07, 2005 12:43 PM - -- To: Raghu Chinthoju - -- Cc: full-disclosure@lists.grok.org.uk - -- Subject: Re: [Full-disclosure] Websites vulnerabilities disclosure - -- - -- On Fri, 07 Oct 2005 14:38:34 +0530, Raghu Chinthoju said: - -- I

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread TheGesus
On 10/7/05, Fielder, Kevin (GE Consumer Finance) [EMAIL PROTECTED] wrote: Surely a better analogy would be... Oh God here we go again. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-07 Thread Stan Bubrouski
On 10/6/05, Georgi Guninski [EMAIL PROTECTED] wrote: On Thu, Oct 06, 2005 at 09:09:32AM +0400, offtopic wrote: snip Which fird-party can't be user as coordinator, like CERT/CC? i recommend you don't use coordinators - they are f*ck*d parasites. think about what they will coordinate -

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-06 Thread Javi Polo
On Oct/06/2005, offtopic wrote: I want to know - is it ethical to use standard vulnerability disclosure policies to public websites? There's no list for what's ethical and what's not ... It's all up to your mind :) (of course your mind's been influenced by lots things, some of them that

Re: [Full-disclosure] Websites vulnerabilities disclosure

2005-10-06 Thread Georgi Guninski
On Thu, Oct 06, 2005 at 09:09:32AM +0400, offtopic wrote: snip Which fird-party can't be user as coordinator, like CERT/CC? i recommend you don't use coordinators - they are f*ck*d parasites. think about what they will coordinate - probably selling your info. cert* sux. -- where do you want

[Full-disclosure] Websites vulnerabilities disclosure

2005-10-05 Thread offtopic
Hi List. I need your opinion. Recently I found multiply vulnerabilities in several sites. some sites behold to security-related firms but not software vendors. I'm trying to contact that companies under rfpolicy several times but don't receive any response on receive something like what