[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.LNX.4.58.0702200958420.6282@dione>
Date: Tue, 20 Feb 2007 10:00:44 +0100 (CET)
From: Michal Zalewski <lcamtuf@...ne.ids.pl>
To: Peter Dawson <slash.pd@...il.com>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Microsoft Internet Explorer Local File
Accesses Vulnerability
On Mon, 19 Feb 2007, Peter Dawson wrote:
> just asking... Is this std practice by vendor to state.... ??? "[..] we
> ask you respect responsible disclosure guidelines and not report this
> publicly...."
It's a common and pretty shameless practice for Microsoft. They also
openly criticize such researchers in media statements (while mentioning
some overly comforting mitigating factors), and then "penalize" you for
not disclosing to them 3-12 months in advance by not crediting you in
vendor bulletins.
These ungrateful researchers, eh?
/mz
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists