Penetration Testing mailing list archives
Fwd: How to report a Vulnerability to a Company
From: "Adam K" <adamk1 () gmail com>
Date: Mon, 14 Jan 2008 15:37:24 -0600
I have been reading this with interest and was just curious about this hypothetical situation. A person goes to use a site and accidentally hits an incorrect key and is given an error page containing important information. At this point would emailing the site owner be an act of pentesting or simply a user reporting an error ? Is there a distinguishable difference ? (I am taking the assumption the user is trying to actively use the site, not looking for errors). ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
Current thread:
- RE: How to report a Vulnerability to a Company, (continued)
- RE: How to report a Vulnerability to a Company Paul Melson (Jan 09)
- RE: How to report a Vulnerability to a Company Thor (Hammer of God) (Jan 09)
- RE: How to report a Vulnerability to a Company Barry Greene (bgreene) (Jan 09)
- Re: How to report a Vulnerability to a Company James Matthews (Jan 09)
- RE: How to report a Vulnerability to a Company Password Crackers, Inc. (Jan 09)
- Re: How to report a Vulnerability to a Company firesidepeavey (Jan 09)
- RE: How to report a Vulnerability to a Company Boaz Shunami (Jan 09)
- Re: How to report a Vulnerability to a Company Ed Telecommuter (Jan 10)
- Re: How to report a Vulnerability to a Company krymson (Jan 10)
- Re: How to report a Vulnerability to a Company Liran Cohen (Jan 14)
- Message not available
- Fwd: How to report a Vulnerability to a Company Adam K (Jan 15)
- Re: How to report a Vulnerability to a Company Liran Cohen (Jan 14)
