Re: Security Exploits...to report, or not to report?

2008-12-25 Thread Sahil Tandon
Modulok wrote: > I was given an FTP account on a server for company X. Being a UNIX > guy, I did some poking around and discovered a security flaw in how > they set their web server up, which would permit anyone at the company > with an FTP account, to intercept ANY data that passed through the >

Re: Security Exploits...to report, or not to report?

2008-12-25 Thread Wojciech Puchar
I was given an FTP account on a server for company X. Being a UNIX guy, I did some poking around and discovered a security flaw in how they set their web server up, which would permit anyone at the company with an FTP account, to intercept ANY data that passed through the company website. Questio

Re: Security Exploits...to report, or not to report?

2008-12-25 Thread APseudoUtopia
On Thu, Dec 25, 2008 at 4:39 PM, Modulok wrote: > List, > > This isn't really FreeBSD related, but I have no one else to consult: > > I was given an FTP account on a server for company X. Being a UNIX > guy, I did some poking around and discovered a security flaw in how > they set their web server

Security Exploits...to report, or not to report?

2008-12-25 Thread Modulok
List, This isn't really FreeBSD related, but I have no one else to consult: I was given an FTP account on a server for company X. Being a UNIX guy, I did some poking around and discovered a security flaw in how they set their web server up, which would permit anyone at the company with an FTP acc