lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <Law10-F117OnYrdH1of00005bcd@hotmail.com>
From: secvar72 at hotmail.com (raj var)
Subject: iDEFENSE Security Advisory 05.22.03: Authentication
 Bypass in iisPROTECT

>
>12/31/2002  Issue disclosed to iDEFENSE
>04/16/2003  E-mail sent to info@...protect.com
>04/16/2003  Response received from David Fearn of iisPROTECT
>04/16/2003  Patch provided to iDEFENSE for verification
>05/22/2003  Coordinated public disclosure
>

EMail sent and patch provided the same day. I hope iDefense had a few good 
reasons to hold on to this for over 100 days before even reporting it to the 
vendor.

SecVar

_________________________________________________________________
MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*.  
http://join.msn.com/?page=features/virus


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ