RE: Informing Companies about security vulnerabilities...

From: mr.nasty@ix.netcom.com
Date: Thu Oct 05 2006 - 16:55:41 EDT


('binary' encoding is not supported, stored as-is) Here's my worthless two cents.

Chances are you are not the first one to discover the problem. Hence unless you do business with them it really doesn't affect you financially. On the other hand the right thing (not the legal thing) to do is inform someone at the company (find many company email addresses - support@company.com etc.) and provide then what you found. NO RECOMMENDATIONS should be offered.

Number one they do not pay you to provide them with Recommendations or solutions.

Number two unless this business affects you financially it's not your burden to bear. And if you do have some financial interest in a company that ignores its customers...LEAVE.

Number three you can't get blood from a turnip or teach pigs to sing.

That’s just my worthless two cents.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:57:07 EDT