lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
From: SkyLined at edup.tudelft.nl (Berend-Jan Wever)
Subject: AOL refuses to help AIM users

Hi all,

McAfee has the same problem. McAfee does the virus-scanning for hotmail. I
discovered a vuln in hotmail a while ago that allowed XSS and wrote a PoC
virus in 100% javascript that would spread itself to everyone in the
addressbook. I informed hotmail about the XSS hole: They fixed the problem
within hours (go Microsoft!).
I also wanted to inform McAfee that they need to update their scanners. I
got a message back asking for my user registration number. I told them I
wasn't a registered user asking for a helpdesk but that I was reporting a
virus which their scanners did not detect. I got back another "We don't read
email without your number..." email.

Berend-Jan Wever

PS. No! The source of the hotmail virus will not be disclosed and it doesn't
work without a XSS hole in Hotmail anyway.

From: "ATD" <simon@...soft.com>


All,
 Has anyone on this list ever tried to report a security issue to AOL? I
just tried to do that and was literally told, "Corporate policy states
that we do not help our free users.". I said, "I suppose thats because
you don't make any money off of the free users".  The man on the other
end of the line being their security expert then stated, "thats right".
Is this how they treat their prospective clients, end users, and free
users? What can we do about this?

--
ATD <simon@...soft.com>
Secure Network Operations, Inc.


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ