Penetration Testing mailing list archives
Re: Publishing Findings on Commercial Applications
From: "Jezebel Ali" <jezebel_ali () hush com>
Date: Wed, 14 Jun 2006 00:20:09 +0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Greetings Brother David MacDonald and other List member, Thanks for response. I must admit that publishing finding makes no sense, yet I look at it from point of view of helping other bank and financial institutes to protect themselves. This findings may save them money by helping do it themselves.
From another point of view, can findings of penetration test that
was conducted at customer premises be used to submit patch request to application vendor for fixes? Would this be consider ethical because invitation was from customer not vendor? Many thank for reading and responding Jez -----BEGIN PGP SIGNATURE----- Note: This signature can be verified at https://www.hushtools.com/verify Version: Hush 2.5 wpwEAQECAAYFAkSPHfkACgkQC68hZJzwc9hGCQP8DoL8k5ji7s/roOS74q7kke4uLVXA stjWXYhsB9VrVjXfCPUg95Ood3nMFlKkMA4EYBP6r+zIxrEYnM4wAQJiFnTguw887UhT qrr0Y1ku/4Qtnag3VqBqbFUcIznr1uJN0BCIBMq5sxAjmvQmCxuILYqOmIYlOcDoItGe vYKNKMA= =MHJv -----END PGP SIGNATURE----- Concerned about your privacy? Instantly send FREE secure email, no account required http://www.hushmail.com/send?l=480 Get the best prices on SSL certificates from Hushmail https://www.hushssl.com?l=485 ------------------------------------------------------------------------------ This List Sponsored by: Cenzic Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details. ------------------------------------------------------------------------------
Current thread:
- RE: Publishing Findings on Commercial Applications, (continued)
- RE: Publishing Findings on Commercial Applications Sahir Hidayatullah (Jun 13)
- RE: Publishing Findings on Commercial Applications Ralph Forsythe (Jun 13)
- Re: Publishing Findings on Commercial Applications Ivan Arce (Jun 14)
- Re: Publishing Findings on Commercial Applications javier (Jun 14)
- Re: Publishing Findings on Commercial Applications Paul Robertson (Jun 13)
- Re: Publishing Findings on Commercial Applications intel96 (Jun 14)
- Re: Publishing Findings on Commercial Applications mikeiscool (Jun 13)
- RE: Publishing Findings on Commercial Applications Paul Melson (Jun 14)
- Re: Publishing Findings on Commercial Applications mikeiscool (Jun 14)
- RE: Publishing Findings on Commercial Applications Paul Melson (Jun 15)
- RE: Publishing Findings on Commercial Applications Paul Melson (Jun 14)
- RE: Publishing Findings on Commercial Applications Sahir Hidayatullah (Jun 13)
- Re: Publishing Findings on Commercial Applications Jezebel Ali (Jun 13)
- Re: Publishing Findings on Commercial Applications Javier Fernandez-Sanguino (Jun 14)
- RE: Publishing Findings on Commercial Applications Jezebel Ali (Jun 14)