Bugtraq mailing list archives
Re: SAP Security Contact
From: "Thor (Hammer of God)" <thor () hammerofgod com>
Date: Tue, 09 Jan 2007 10:21:43 -0800
On 1/6/07 4:14 PM, "Nicob" <nicob () nicob net> spoketh to all:
Le vendredi 05 janvier 2007, Thor (Hammer of God) a écrit :Something like security () sap com may seem obvious, but it's better if you list specific contact info so it can be easily found.I don't want to be rude but : - security () domain tld is the only standardized security contact (as defined by RFC 2142) - googling security () sap com would bring some results - this was already answered on the Full-Disclosure mailing list - the OSVDB Vendor Dictionary contains a record for SAP - even the SecurityFocus site has some references to this email address : http://www.securityfocus.com/columnists/415
You're not being rude at all-- that was my point about security () sap com "being somewhat obvious." RFC states the use of a "security" mailbox. But in the absence of any official reference, you really don't know if it is a valid contact or not. The main point was that when someone goes to a vendor's domain and clicks "contact us" there should be a security reference there. That fact is evident when you consider that this thread wouldn't exist in the first place had SAP simply provided that information. A security researcher shouldn't have to Google various machinations of possible security contact references, nor should they have to search off-site security portals (and have to trust the results) to see if a particular email address exists when it is trivial to stick a link on vendor's "official" page... It's really not that big of a deal. t
Current thread:
- SAP Security Contact Mark Litchfield (Jan 04)
- <Possible follow-ups>
- Re: SAP Security Contact Fritz . Bauspiess (Jan 05)
- Re: SAP Security Contact Thor (Hammer of God) (Jan 06)
- Re: SAP Security Contact Ansgar -59cobalt- Wiechers (Jan 08)
- Re: SAP Security Contact Nicob (Jan 08)
- Re: SAP Security Contact Stan Bubrouski (Jan 09)
- Re: SAP Security Contact Nick Boyce (Jan 10)
- Re: SAP Security Contact Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (Jan 11)
- Re: SAP Security Contact Thor (Hammer of God) (Jan 10)