[Full-disclosure] Websites vulnerabilities disclosure
Stan Bubrouski
stan.bubrouski at gmail.com
Fri Oct 7 22:12:50 BST 2005
On 10/6/05, Georgi Guninski <guninski at guninski.com> wrote:
> On Thu, Oct 06, 2005 at 09:09:32AM +0400, offtopic wrote:
> > <snip> Which fird-party can't be user as coordinator, like CERT/CC?
>
> i recommend you don't use coordinators - they are f*ck*d parasites.
> think about what they will "coordinate" - probably selling your info.
> cert* sux.
I really agree with this. When you're a researcher who puts the time
in to discovering, exploiting, and sometimes fixing a vulnerability,
you've done the work, why let them steal the credit?
There are times when you find holes that you report to one of these
services because you have no time or motivation to do the research
yourself. But if you want the credit for what you've done or even
feedback then writing up your own advisory or working on one with a
vendor is a much better solution. After all, what do these services
offer that you can't do yourself?
Best Regards,
sb
>
> --
> where do you want bill gates to go today?
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
Full-Disclosure is hosted and sponsored by Secunia.