lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
From: hamster at proftpd.org (Mark Lowes)
Subject: Re: The Cult of a Cardinal Number

On Tue, 2004-03-02 at 05:37, Phantasmal Phantasmagoria wrote:
> - ---- Final thoughts ----------------
> It is difficult, if not impossible, to please every group of the security
> community when releasing information pertaining to a vulnerability. Some
> will say that I should of contacted the vendor, some will say I should
> of kept the bug to myself, some will say I should of released exploit
> code. I can only offer one account; The Cult of a Cardinal Number has
> finished. It was found, exploited, and patched. And it has finished.

A cc of this email to security@...ftpd.org would have been appreciated
if you felt the need not to give any prior warning to the team so
problematic versions could be removed from the ftp archives and/or
patched.

    Mark Lowes

-- 
Mark Lowes <hamster@...ftpd.org>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ