Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception |
|---|---|
| Date: | Fri, 26 Nov 2004 14:45:22 -0500 (EST) |
On Thu, 25 Nov 2004, Heikki Toivonen wrote:
3. Either login if you already have an account, or click "create new account". Let's assume we need to create a new account... 4. Type in a valid email address and click "Create Account" 5. [mail] Read email that was sent to the address to get password 6. back on in the browser, click "log in here" 7. fill in your username and password and click "login"
[snip the rest of useful info on how to post good, healthy, actionable bug
reports]
requiring someone to register to post a bug is harmful in the sense that
you wind up turning off peopl ewho simply can't be bothered to fill out
that info or wish to remain anonymous. while i definitely see the benefit
of forcing registration or even wanting it, i bet you'e losing more bug
reports than you care to imagine this way.
benefits of forcing/encouraging registration include:
- garaunteed line of followup
- reduced spam quantities in bugzilla
- at leasta cutofof "i care enough to ..."
still, you're losing more than you may expect. i know i've failed to file
bug reports (non-security related) for mozilla products due to this "speed
bump". the security@ route is useful, and i'm glad you pointed it out.
this point should be considered by anyone who runs a bug reporting page
for open submissions, you may be doing more harm than benefit.
________
jose nazario, ph.d. jose@monkey.org
http://monkey.org/~jose/ http://infosecdaily.net/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
| Previous by Date: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation, David Vincent |
|---|---|
| Next by Date: | RE: [Full-Disclosure] Mailing lists and unsolicited/malicious spam, Todd Towles |
| Previous by Thread: | Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception, Heikki Toivonen |
| Next by Thread: | Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception, Heikki Toivonen |
| Indexes: | [Date] [Thread] [Top] [All Lists] |