lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 31 May 2006 09:20:43 -0400
From: John F Flynn III <flynnj@...fiu.edu>
To: support@...selscripts.com
Cc: bugtraq@...urityfocus.com
Subject: Re: [Info Disclosure] Diesel PHP Job Site Latest Version


As a systems administrator, I must say that your methods are 
unacceptable. You are violating your customers' trust by doing this 
without their knowledge. You even made an effort to hide the code that 
sends the information! This is outright deceit and should not be 
tolerated by anyone.

Regardless of your motives, this deceitfulness must be exposed for all 
to know about.

Perhaps you should trust your customers more. As word of this gets out, 
you are likely to have a lot fewer of them. I just feel sorry for those 
who do not find out in time and have their systems compromised because 
login credentials and other information were sent clear-text over the 
Internet.

-John

support@...selscripts.com wrote:
> Hello,
> 
> To explain this to all visitors, the information is used to prevent any unauthorized copies from running on the web.
> 
> All of the php developers that sell products online use this method or even more methods.
> 
> Please stop making such a big deal out of this because it's our way of protecting our work and business.
> 
> Thank you for understanding !
> 
> DieselScripts Staff
> www.dieselscripts.com

-- 
John Flynn                              flynnj@...fiu.edu
=========================================================
Systems and Network Administration             /\_/\
School of Computer Science                    ( O.O )
Florida International University               >   <


Powered by blists - more mailing lists