|
|
|
|
|
by jolmg
2346 days ago
|
|
It's a bit funny how timeattack is trying to not disclose the nature of the bug publicly and goes through the trouble of sending a private email and notifying here, then you spill the beans publicly in a reply. :D It might be obvious to many, but to many more it would not be. It just raises the chances of someone exploiting it before anderspitman fixed it. Window was pretty small though, so that's good. |
|
Nevertheless, I am respectful of responsible security disclosure. Maybe timeattack will prefer to use an entirely private channel to communicate with the server owner the next time?
In the end, the info was already out, the author fixed it real quick and I hoped he has cleaned its server by now ;)