Hello Google et al, I have devised a proof-of-concept via Cross-Site Request Forgery that allows arbitrary unvalidated attackers to disrupt Google Apps email on any domain. For my time and research into this issue, I am offering to sell the vulnerability to you at a fair price compensation, within the next week. If I do not receive an offer to purchase prior to June 14, I will presume that you are not interested in patching this vulnerability or acquiring my intellectual property. At that time, I will sell it on the open market. Please let me know how you would like to proceed.
Regards, -- Kristian Erik Hermansen _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
