[VulnDiscuss] CERT

"Mark Litchfield" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq
Message-ID <002701c2c710$5a713d10$0100a8c0@liberty>
Copy of mail sent to CERT:

Dear CERT,

It has come to my attention, that the 6 vulnerabilities that I recently submitted to the vendor and yourselves has been leaked to certain organisations and government departments.  I know this as the vendor has asked whether I knew the following, and has also voiced to me their views on your actions:

Vendor Quote:

"By the way, were you aware of CERT's policy of advance disclosure to certain parties?"

In submitting vulnerabilities to yourselves, I do so as an act of good faith to encourage the communication of the vulnerability to the IT administrators that it will affect with a view to increasing the patch uptake.  I do not expect the issue to be disclosed to any parties; I believe that this choice remains with the discoverer or discovering company and the vendor of the software.

I consider these actions made by yourselves as unprofessional, and as far as I am concerned I feel a betrayal in the trust that was extended to your organisation by myself.

It is with great regret, that based on your actions, NGS software who published 47 vulnerabilities in 2002, will no longer support CERT in any fashion.

Despite being a competitor, I think it only fair to mention that ISS's reasons for not wishing to inform CERT on the Apache Transfer Encoding Chunked Issue have now been clearly justified.

I am posting this to the mailing lists so that independent or corporate researchers are aware of your practice.  I just hope that the other organisations offering a similar service as a Vulnerability pre-disclosure clearing house are not following the same path.

Regrettably

Mark Litchfield
NGS Software Ltd
http://www.ngssoftware.com/
Tel: +44 208 40 100 70 (London)
Tel: +44 1241 431 267
Mobile: +44 790 069 5236
Email: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.