OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Dailydave] 0x43434343

From: David Maynor (dave0dayspray.com)
Date: Thu Nov 20 2003 - 13:01:59 CST


> >The thing about about bugtraq is that it has 50K subscribers, and no
> >other mailing list even comes close. So if you want to get your name
> >out, you post to bugtraq. Of course, they then hold your mail for 2 days
> >while they make money off it,
>
> That's an unproven assumption. They are very aware that people are
> looking to see if that takes place, so I believe they are careful to not
> do so. When I was there, at best we would find out about it the moment
> Dave decided to approve it or not (I believe I can remember one or two
> occasions when I got to see a rejected post, to look at some technical
> bit. There were a couple of occasions when we were asked to quickly
> help analyze some code for trojaness before it was approved.) Dave
> would sometimes forward a post just after he approved it, which saved up
> the time of having to wait for the mailing list to get to our addresses,
> which could save us as much as two hours or so.
>
> Obviously, this could have changed at any point in the last year or so
> since I've been gone, but I'm willing to give Dave the benefit of the
> doubt until it is demonstrated otherwise. Of course, if they cross-post
> to FD, then the analysts at SF get a copy right away anyway, so there's
> no opportunity for collusion.
>
I can think of at least one case where it happened in June of this year
with stuff involving the window size of 55808 showing up everywhere.