OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: Digg Security.

From: Rocky (rocky.heg-wizinnovations.com)
Date: Thu May 11 2006 - 21:47:40 CDT


I hope this wasn't just a case of them trying to cover up their problem by
claiming it wasn't a problem publicly while scrambling to fix it behind
closed doors. I hate it when people try to get sneaky that way. Just admit
it and be a good example of listening to those that cared enough to report
it properly.

-----Original Message-----
From: Jon Keating [mailto:jonkeatinggmail.com]
Sent: Friday, 12 May 2006 12:39 PM
To: stevequicksilverscreen.com
Cc: vuln-devsecurityfocus.com
Subject: Re: Digg Security.

On 11 May 2006 21:17:07 -0000, stevequicksilverscreen.com
> In an email I recieved later one of their developers told me that unless I
can show them otherwise, they would not consider this a security problem,
and would not fix it.

Looks like they did take you seriously, I copied your HTML source to
my own server and accessed the page. When I get sent to Digg.com it
gives this error:

Incident has been logged - hope you enjoyed the site while you had a chance

Jon