RE: Publishing Findings on Commercial Applications

From: Ralph Forsythe (rforsythe@5280tech.com)
Date: Tue Jun 13 2006 - 18:58:17 EDT


Another question to answer -- Would disclosing the information discovered
put your client at potential risk?

I'm not sure of the legal ramifications of disclosing a flaw you found
(even if identifiable information were removed) during a contracted
pen-test, versus one you found in your own free time. If the client then
gets violated through your discovery by chance just because of what they
do, it's conceivable that they could have a case against you. Yeah I know
people disclose vulnerabilities daily, but generally those people aren't
being paid by potential targets to find the holes either.

In a roundabout way, you'd be telling the world "here's how to hack my
client" even without disclosing their name, if that software package is as
pervasive as you say it is. I know if I were a bank and this happened to
me, I'd have my legal counsel on the phone in about 3.2 seconds, if even
to find out I had no case (but I'd still be looking very hard at it).

If you are 100% sure you have nothing contractual barring it, I'd still
consult a lawyer to make sure you aren't setting yourself up for a bad
time. Ethically (and perhaps legally as well) I think contacting the
vendor first is probably the best path to take. That doesn't mean you
can't disclose it publically, but you may come to an agreement on delaying
that email while they prepare a patch. You'll also be more of a fan to
those banks' customers, who will appreciate the immediate response rather
than waiting an indeterminate amount of time during which their accounts
could be vulnerable to who knows what.

- Ralph

On Wed, 14 Jun 2006, Sahir Hidayatullah wrote:

> Might be a better idea to contact the vendor first.
> These days you can get into all sorts of trouble for revealing flaws.
>
> Besides, it's probably more ethical to work with them first isn't it ? :)
>
> You could also follow RFP's disclosure policy:
> http://www.wiretrip.net/rfp/policy.html
>
> Regards,
>
> --S.
>
>
> -----Original Message-----
> From: Jezebel Ali [mailto:jezebel_ali@hush.com]
> Sent: Wednesday, June 14, 2006 1:00 AM
> To: pen-test@securityfocus.com
> Subject: Publishing Findings on Commercial Applications
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Greetings Brother and Sister List Members,
>
> I have question: If I performing Penetration Test on customer site
> and this customer has a commercial application which is not
> publicly available for download or purchase, do I have a right to
> publish finding of this application to the public without
> mentioning customer name?
>
> This application widely used by banking and financial industry and
> not always available to anyone for testing.
>
> Kind regards,
> Jez
> -----BEGIN PGP SIGNATURE-----
> Note: This signature can be verified at https://www.hushtools.com/verify
> Version: Hush 2.5
>
> wpwEAQECAAYFAkSPEjEACgkQC68hZJzwc9hmzQP/XdSnsXhREbRPUQsCyDrabyaRQb7A
> h2c617zR73xrSAlyXROxP6tJhxfLKiNkNKRb6yfNEJMcYQyr+nduJDoG/9FIix1hVns2
> WewlBCrufnT3ZNcLa7+KNeHYpMkhHPcAop9NjUJDgUILQwbJLzv7cWPK5wcz74eYwCkF
> 5Q4IqlE=
> =jFJM
> -----END PGP SIGNATURE-----
>
>
>
>
> Concerned about your privacy? Instantly send FREE secure email, no account
> required
> http://www.hushmail.com/send?l=480
>
> Get the best prices on SSL certificates from Hushmail
> https://www.hushssl.com?l=485
>
>
> ----------------------------------------------------------------------------
> --
> This List Sponsored by: Cenzic
>
> Concerned about Web Application Security?
> Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
> Choice Award from eWeek. As attacks through web applications continue to
> rise,
> you need to proactively protect your applications from hackers. Cenzic has
> the
> most comprehensive solutions to meet your application security penetration
> testing and vulnerability management needs. You have an option to go with a
> managed service (Cenzic ClickToSecure) or an enterprise software
> (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
> help you: http://www.cenzic.com/news_events/wpappsec.php
> And, now for a limited time we can do a FREE audit for you to confirm your
> results from other product. Contact us at request@cenzic.com for details.
> ----------------------------------------------------------------------------
> --
>
>
>
> ------------------------------------------------------------------------------
> This List Sponsored by: Cenzic
>
> Concerned about Web Application Security?
> Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
> Choice Award from eWeek. As attacks through web applications continue to rise,
> you need to proactively protect your applications from hackers. Cenzic has the
> most comprehensive solutions to meet your application security penetration
> testing and vulnerability management needs. You have an option to go with a
> managed service (Cenzic ClickToSecure) or an enterprise software
> (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
> help you: http://www.cenzic.com/news_events/wpappsec.php
> And, now for a limited time we can do a FREE audit for you to confirm your
> results from other product. Contact us at request@cenzic.com for details.
> ------------------------------------------------------------------------------
>
>
>

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:56:05 EDT