Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Exploit Code on Trial
Kevin Poulsen, SecurityFocus 2003-11-23

Security pros gathering at a Stanford University Law School conference on responsible vulnerability disclosure Saturday harmonized on the principle that vendors should be privately notified of holes in their products, and given at least some time to produce a patch before any public disclosure is made. But there was pronounced disagreement on the question of whether or not researchers should publicly release proof-of-concept code to demonstrate a vulnerability.

Comments Mode:
Exploit Code on Trial 2003-11-24
Anonymous
Screw the vendors 2003-11-24
Anonymous (2 replies)
Screw the vendors 2003-11-25
Rodrigo Otaviano <rodrigo (at) otaviano (dot) com [email concealed]>
Well, I think the best way to approach this kind of situation is by firstly contacting the vendor and trying to work with them. When I say "work with them" I mean you need to demonstrate that you are interested in having a fast solution to the problem.

I've recently gone through a similar situation. I found a minor security flaw on a product of a certain big company (I prefer to not expose them right now because they are still in process of fixing it) and they've been very nice with me.

They not only asked me further information about the program I had developed to attack this product in question, but also sent me the first patch to test it, even without releasing it publicly.

I know that some companies don't give a sh** when they receive emails describing problems on their products, but I believe it's just a matter of "how to talk to them", because they certainly know the importance of this "independent" help ( at least I believe so ... )

Rodrigo Otavio Paes de Barros Otaviano

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/7511/23870#23870
Exploit Code on Trial 2003-11-24
Bob Radvanovsky
Exploit Code on Trial 2003-11-24
Anonymous
Exploit Code on Trial 2003-11-24
TW
Exploit Code on Trial 2003-11-25
Leif Ericksen
Exploit Code on Trial - final word 2003-11-25
Anonymous (1 replies)
Exploit Code on Trial 2003-11-25
Camel
Loss of money 2003-11-29
bl0rf
Exploit Code on Trial 2003-12-02
Anonymous
Exploit Code on Trial 2003-12-02
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus