<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; disclosure</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/disclosure/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>full disclosure for public web apps</title>
		<link>http://angelsofsecurity.com/blog/2010/05/21/full-disclosure-for-public-web-apps/</link>
		<comments>http://angelsofsecurity.com/blog/2010/05/21/full-disclosure-for-public-web-apps/#comments</comments>
		<pubDate>Fri, 21 May 2010 20:08:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[web apps]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/?p=589</guid>
		<description><![CDATA[There&#8217;s a new full disclosure website in town &#8211; http://www.vs-db.info names and shames those with web application vulnerabilities (like SQL injection, XSS, XSRF, CRLF injection, etc.), without providing enough details for exploit.]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a new full disclosure website in town &#8211; <a href="http://www.vs-db.info">http://www.vs-db.info</a> names and shames those with web application vulnerabilities (like SQL injection, XSS, XSRF, CRLF injection, etc.), without providing enough details for exploit.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2010/05/21/full-disclosure-for-public-web-apps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>no more free bugs</title>
		<link>http://angelsofsecurity.com/blog/2009/04/02/no-more-free-bugs/</link>
		<comments>http://angelsofsecurity.com/blog/2009/04/02/no-more-free-bugs/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 20:28:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[disclosure]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/04/02/no-more-free-bugs/</guid>
		<description><![CDATA[A very interesting development in the disclosure debate. A few weeks ago, Charlie Miller, Alex Sotirov, and I [Dai Zovi] arrived on a new meme: No More Free Bugs. Therefore, reporting vulnerabilities for free without any legal agreements in place is risky volunteer work.  There are a number of legitimate alternatives to the risky proposition [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://blog.trailofbits.com/2009/03/22/no-more-free-bugs/">very interesting development</a> in the disclosure debate.</p>
<blockquote><p>A few weeks ago, <a href="http://blogs.zdnet.com/security/?p=2941">Charlie Miller</a>, <a href="http://www.phreedom.org/">Alex Sotirov</a>, and I [Dai Zovi] arrived on a new meme: No More Free Bugs.</p>
<p>Therefore, reporting vulnerabilities for free without any legal agreements in place is risky volunteer work.  There are a number of legitimate alternatives to the risky proposition of volunteering free vulnerabilities and I have already mentioned a few (I don’t want to turn this into an advertisement or discussion on the best/proper way to monetize security research).   There just need to be more legal and transparent options for monetizing security research.  This would provide a fair market value for a researcher’s findings and incentivize more researchers to find and report vulnerabilities to these organizations.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/04/02/no-more-free-bugs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>vulnerability disclosure response time</title>
		<link>http://angelsofsecurity.com/blog/2009/03/05/vulnerability-disclosure-response-time/</link>
		<comments>http://angelsofsecurity.com/blog/2009/03/05/vulnerability-disclosure-response-time/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 20:45:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[disclosure]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/03/05/vulnerability-disclosure-response-time/</guid>
		<description><![CDATA[A few months ago I found a XSS vulnerability in a product used by many people. I contacted the vendor, which happens to be a very large entity. (No, it&#8217;s not Microsoft, but that&#8217;s the only hint I&#8217;ll give). Here&#8217;s the timeline of what&#8217;s happened so far: Dec 18 2008 &#8211; I send an email [...]]]></description>
			<content:encoded><![CDATA[<p>A few months ago I found a XSS vulnerability in a product used by many people. I contacted the vendor, which happens to be a very large entity. (No, it&#8217;s not Microsoft, but that&#8217;s the only hint I&#8217;ll give). Here&#8217;s the timeline of what&#8217;s happened so far:</p>
<ul>
<li> Dec 18 2008 &#8211; I send an email informaing them of the problem, and showing them what was needed to replicate it.</li>
<li>January 8 2009 &#8211; They sent me a response saying they were &#8220;evaluating and will get back to me&#8221;.</li>
<li>Feb 12 2009 &#8211; I send a followup email asking what&#8217;s going on.</li>
<li>March 5, 2009 &#8211; I get a response saying that they have verified the issue, and are working on a fix.</li>
</ul>
<p>So, does this seem like a reasonable timeline? Should I be pushing harder? This isn&#8217;t the biggest vulnerability in the world, but it still seems like something that should be fixed, and the fix shouldn&#8217;t be that hard.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/03/05/vulnerability-disclosure-response-time/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>MS09-002 reverse engineered</title>
		<link>http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/</link>
		<comments>http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/#comments</comments>
		<pubDate>Tue, 17 Feb 2009 20:42:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/</guid>
		<description><![CDATA[ISC is reporting that they&#8217;re seeing exploits of MS09-002 in the wild. MS09-002 is an exploit which allows for remote code execution on IE7. The vulnerability was first reported to MS in October of 2007 by the Zero Day Initiative. Microsoft issued the patch a week ago. Given this, ISC is also claiming that it [...]]]></description>
			<content:encoded><![CDATA[<p>ISC is <a href="http://isc.sans.org/diary.html?storyid=5884">reporting</a> that they&#8217;re seeing exploits of <a href="http://www.microsoft.com/technet/security/bulletin/MS09-002.mspx">MS09-002</a> in the wild. MS09-002 is an exploit which allows for remote code execution on IE7. The vulnerability was first <a href="http://www.zerodayinitiative.com/advisories/ZDI-09-012/">reported to MS</a> in October of 2007 by the Zero Day Initiative. Microsoft issued the patch a week ago. Given this, ISC is also claiming that it is likely that the patch was reverse engineered to find the vulnerability, and I would have to agree. I&#8217;m sure the anti-disclosure crowd will be using this one as proof positive for their position in the future.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

