BugTraq
MSIE src&name property disclosure Nov 08 2004 11:40AM
Berend-Jan Wever (skylined edup tudelft nl) (1 replies)
Re: [Full-Disclosure] MSIE src&name property disclosure Nov 08 2004 02:13PM
Michal Zalewski (lcamtuf ghettot org) (2 replies)
Re: [Full-Disclosure] MSIE src&name property disclosure Nov 08 2004 07:33PM
Paul Schmehl (pauls utdallas edu) (1 replies)
Re: [Full-Disclosure] MSIE src&name property disclosure Nov 08 2004 08:37PM
Michal Zalewski (lcamtuf coredump cx)
On Mon, 8 Nov 2004, Paul Schmehl wrote:

[ Moderators - feel free to kill this ]

> Never attribute to malice what can be explained by incompetence. Most
> likely what happened is the left hand (PR) didn't know what the right
> hand (secure@) was doing.

Highly unlikely; Microsoft Security Response is a team that, among other
things, manages and handles security response, including security-related
PR-esque functions (ever seen 'security evangelist' job postings on the
net?). The quote is fairly specific, so I doubt it could be spawned by a
lone PR drone who did not check with them.

--
------------------------- bash$ :(){ :|:&};: --
Michal Zalewski * [http://lcamtuf.coredump.cx]
Did you know that clones never use mirrors?
--------------------------- 2004-11-08 21:35 --

http://lcamtuf.coredump.cx/photo/current/

[ reply ]
Re: [Full-Disclosure] MSIE src&name property disclosure Nov 08 2004 02:48PM
Dave Aitel (dave immunitysec com)


 

Privacy Statement
Copyright 2010, SecurityFocus