I've discovered a security hole in the current Perl Monks website.
Now - where do I report this?
I know the code behind the site is derived from that on Everything, so I'm reasonably sure that it would apply to their site also. (But without having an account there it's hard to verify).
Clearly I do not wish to post details out in the public - so I'm asking this question here.
You can contact me in many ways - even using my GPG Key if you wish.
Interesting problem: I wish to report the issue to somebody with power to fix it (quickly) and can verify who I am. How do I trust the person who contacts me is who they say they are ..? ;)
Steve
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Where to report a security hole?
by data64 (Chaplain) on Mar 14, 2003 at 22:23 UTC | |
by skx (Parson) on Mar 14, 2003 at 22:58 UTC | |
by djantzen (Priest) on Mar 15, 2003 at 01:22 UTC | |
by fruiture (Curate) on Mar 15, 2003 at 10:47 UTC |