Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: The non-apreciated world of full-disclosure

The non-apreciated world of full-disclosure

From: Davide Del Vecchio <dante_at_alighieri.org>
Date: Wed, 03 Mar 2004 09:33:04 +0100

16 days after my post regarding the Firewall/VPN Appliance vuln
and 1 month more my TELEPHONE notice to Symantec support,
Symantec released a new version of firmware for their appliance.
But the problem it`s not the time.
The problem is that they told me it was "not a vulnerability",
after 1 month they released the new firmare to patch the "Cached Password
Vulnerability" (as they called it), and just telling
"Symantec is aware of a potential administrator password leakage
vulnerability reported in
<http://securitytracker.com/alerts/2004/Feb/1009069.html>."

...

This is what I received..I don`t want money
but I think an ufficial "thank you" is the minimum... or not?
Am I telling something of MAD?!

the new firmware is avaiable here:

ftp://ftp.symantec.com/public/english_us_canada/products/symantec_firewall_v
pn_appliance/updates/vpn200_161_app.zip

d.

 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Davide Del Vecchio "Dante Alighieri" dante_at_alighieri.org ~ dante_at_bluejack.it
http://www.alighieri.org http://www.bluejack.it http://www.ezln.it
 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Received on Mar 03 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]