CyberArmy University | Open Source Institute | CyberArmy Intelligence & Security | CyberArmy Services & Projects

RE: Development Teams Reply


[Replies] [Reply] [View by Thread] [Help]
[Back To Security]

Posted by Ker JeiAr On 2004-03-23 17:31:30
In Reply to RE: Development Teams Reply Posted by Ker JeiAr On 2004-03-23 17:17:53

Ker
Ker JeiAr

www.gulftech.org/images/brute.jpg


I just sent Paul this. I wonder what he will say.


Hi Paul,

I just read this.
I should add that I did not give permission for the original reporter to disclose my email conversations with him ... I could have persued that if I'd wished. However I decided it may help explain the situation and thus let it go.
If you did not like me posting your email why not tell ME instead of saying something about it to people who were not even involved in the correspondance on your forum?


> I don't mean this to sound like we don't want to do anything, it's just that there is no great need to in 2.0. So please,
> should you chose to release anything detailing "security problems" please be sure to emphasise the underlying issue as to
> why they are of very little concern.

---------------

I will release details of this email and try and show things from all points of view. I just want to help people, not
frighten them or make them think phpBB is insecure. After all we use phpBB for the GulfTech forums ;)

---------------
This was the EXACT same thing I sent to you. You knew I was gonna release the email, why didn't you ask "JeiAr, can I give you a official response to post instead of the email?" I would have glady done that instead. I have always been a fan of phpBB, and I have given advance warning on vulns I have found because I like users to be safe, and I like helping the Open Source community. But I would be lying if I said that I wasn't a little dissapointed over the handling of this issue.

Fine, you have your mind made up and some users agree? Okay, thats the way it is, and I will write my own patch. But I have been nothing but professional and curteous to you and you should realize if you have a problem with me (the releasing of your email) then tell me about it. I am an adult, and not a jerk. If you want your email removed all you had to do was ask ME. If you would like I can replace it with your response on the announcment forums.


Best Regards,

James


GulfTech Security Research
SubScan 1.2



Replies:


Guest:
Subject:
Message:
Signature:
Optional Image Link:
http://

CyberArmy::Forum v0.6
Generated In 0.05258 seconds


About Us | Privacy Policy | Mission Statement | Help