Re: Found a security issue

2020-01-16 Thread Willy Tarreau
On Thu, Jan 16, 2020 at 12:49:40PM +0100, Tim Düsterhus wrote: > Willy, > > Am 15.01.20 um 21:07 schrieb Willy Tarreau: > >> maybe > >> even a security.txt file: https://securitytxt.org/ > > > > Thanks for this link. I never heard about this one. Did you hear about > > anyone using it yet ? > >

Re: Found a security issue

2020-01-16 Thread Tim Düsterhus
Willy, Am 15.01.20 um 21:28 schrieb Willy Tarreau: > OK for those publishing it, but anyone looking there for a contact ? I > mean, when someone cannot just "git log" or "git blame" in an opensource > project to figure the people who touched the same area recently, I doubt > they'll ever know abou

Re: Found a security issue

2020-01-16 Thread Tim Düsterhus
Willy, Am 15.01.20 um 21:07 schrieb Willy Tarreau: >> maybe >> even a security.txt file: https://securitytxt.org/ > > Thanks for this link. I never heard about this one. Did you hear about > anyone using it yet ? Rumor has it that it is used to automatically send bogus vulnerabilities that fell

Re: Found a security issue

2020-01-15 Thread Julien Pivotto
On 15 Jan 21:07, Willy Tarreau wrote: > Hi Julien, > > even a security.txt file: https://securitytxt.org/ > > Thanks for this link. I never heard about this one. Did you hear about > anyone using it yet ? https://www.facebook.com/security.txt https://www.google.com/.well-known/security.txt > >

Re: Found a security issue

2020-01-15 Thread Willy Tarreau
On Wed, Jan 15, 2020 at 08:51:26PM +0100, Willy Tarreau wrote: > On Wed, Jan 15, 2020 at 10:06:12PM +0800, ZeddYu Lu wrote: > > Hi. I found a security issue about the latest haproxy. How can I > > report this? > > Just a quick update on this one, I got it and it was just a false alarm. By the way

Re: Found a security issue

2020-01-15 Thread Willy Tarreau
On Wed, Jan 15, 2020 at 12:20:08PM -0800, LCF wrote: > On Wed, Jan 15, 2020 at 12:07 PM Willy Tarreau wrote: > > > > maybe > > > even a security.txt file: https://securitytxt.org/ > > > > Thanks for this link. I never heard about this one. Did you hear about > > anyone using it yet ? > > > > Som

Re: Found a security issue

2020-01-15 Thread LCF
On Wed, Jan 15, 2020 at 12:07 PM Willy Tarreau wrote: > > maybe > > even a security.txt file: https://securitytxt.org/ > > Thanks for this link. I never heard about this one. Did you hear about > anyone using it yet ? > Some examples: https://www.dropbox.com/.well-known/security.txt https://www.

Re: Found a security issue

2020-01-15 Thread Willy Tarreau
Hi Julien, On Wed, Jan 15, 2020 at 08:56:32PM +0100, Julien Pivotto wrote: > On 15 Jan 20:51, Willy Tarreau wrote: > > On Wed, Jan 15, 2020 at 10:06:12PM +0800, ZeddYu Lu wrote: > > > Hi. I found a security issue about the latest haproxy. How can I > > > report this? > > > > Just a quick update o

Re: Found a security issue

2020-01-15 Thread Julien Pivotto
On 15 Jan 20:51, Willy Tarreau wrote: > On Wed, Jan 15, 2020 at 10:06:12PM +0800, ZeddYu Lu wrote: > > Hi. I found a security issue about the latest haproxy. How can I > > report this? > > Just a quick update on this one, I got it and it was just a false alarm. > > Willy > we could improve http

Re: Found a security issue

2020-01-15 Thread Willy Tarreau
On Wed, Jan 15, 2020 at 10:06:12PM +0800, ZeddYu Lu wrote: > Hi. I found a security issue about the latest haproxy. How can I > report this? Just a quick update on this one, I got it and it was just a false alarm. Willy