
Full Disclosure mailing list archives
Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere)
From: Taylor Burke <jburke () liquidweb com>
Date: Tue, 23 Apr 2013 12:39:27 -0400
Someone earlier (in another thread?) mentioned notifying the vendor first and, if they don't respond within a week or some other reasonable period of time, going public with the 0day and a clear conscious. And I completely agree- at least make an effort to let the vendor know before you go public.
On 13-04-23 10:51 AM, Georgi Guninski wrote:
Completely disagree. IMHO nobody should bother negotiating with terrorist vendors. Q: What responsibility vendors have? A: Zero. Check their disclaimers. On Tue, Apr 23, 2013 at 04:14:53PM +0200, Gregory Boddin wrote:That's indeed not rocket science. Nobody should release their disclosure/exploit (or give hint about it) in the wild before letting the vendor fix it. There's already enough blackhats out there selling/using those. I sure hope I am not the only person in the list who wishes responsibledisclosure. --- Henri Salo -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAlF2eWAACgkQXf6hBi6kbk8p+QCgkrzZnNpipCMC/kexFq8OR3Q2 NiIAnRMYicxFqmJhvjLIEZolEKjQcEEE =q78V -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
-- Regards, Taylor Burke /* * Taylor Burke * Linux Systems Administrator * * Liquid Web, Inc. - www.Liquidweb.com * support () liquidweb com * Knowledge Base: http://kb.liquidweb.com/ * * 800-580-4985 Toll-Free - 517-322-0434 Int. */ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere), (continued)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) dawg (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Georgi Guninski (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Gregory Boddin (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Georgi Guninski (Apr 24)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Valdis . Kletnieks (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Gary Baribault (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Tavis Ormandy (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Valdis . Kletnieks (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Tavis Ormandy (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Georgi Guninski (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Taylor Burke (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Gary Baribault (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Valdis . Kletnieks (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Mark Felder (Apr 23)
- Re: 0day Vulnerability in VLC (this is my first release of the vuln anywhere) Tavis Ormandy (Apr 23)