Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Guesswork Plagues Web Hole Reporting
Kevin Poulsen, SecurityFocus 2002-03-06

A good Samaritan has trouble getting the attention of a fashion retailer leaking customer credit card numbers. Should reporting security holes in e-commerce sites be easier?

Comments Mode:
Guesswork Plagues Web Hole Reporting 2002-03-06
Anonymous (4 replies)
Guesswork Plagues Web Hole Reporting 2002-03-07
Tommy Ward
I completely sympathize with anyone who has tried to contact a human being at many large organizations. It can really be difficult. The default stance seems to be "send us an order", or do you want to "order something".

To be fair to the companies, however, I know what type of insane crap comes in when you have a public contact point, not to mention the spam that gets sent to any machine recognizable email address on a web site. For a large site, it would take a full time person just to sort through the inbox. And of course, most organizations certainly don't have much security awareness outside of a few key personnel.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/346/10843#10843
Guesswork Plagues Web Hole Reporting 2002-03-08
Anonymous (1 replies)
Guesswork Plagues Web Hole Reporting 2002-03-13
Andrew Daviel







 

Privacy Statement
Copyright 2009, SecurityFocus