Annoyed at delays from JSST

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
yehgnet
Joomla! Apprentice
Joomla! Apprentice
Posts: 21
Joined: Thu Dec 11, 2008 12:51 pm
Location: MM
Contact:

Annoyed at delays from JSST

Post by yehgnet » Fri Oct 01, 2010 6:49 am

Hi Joomla! Security Strike Team (JSST - or top-notch security experts)

We submitted few issues at Sat, Sep 11, 2010 to security at joomla.org.

We got your response (Claire Mandville) at Wed, Sep 15, 2010 (Claire told us they would look at the issues) .

Therefore, we asked your status at Sep 18, 2010 through security at joomla.org.
We didn't get any status from you.

Again we asked your status at Sep 27, 2010 through http://developer.joomla.org/security/co ... -team.html.
Again we didn't get any status from you.

Now we've assumed that Joomla! ignored our report and we'll publicize the vulnerability information accordingly in a few days soon at Full Disclosure and BugTraq Mailing lists.
Sorry for excuse like 'Your report was in SPAM and we've now got it'.


Regards
YEHG
Last edited by mandville on Fri Oct 01, 2010 9:23 am, edited 1 time in total.
Reason: retitled under forum rules.

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: There is no PATCH for Ignorance!

Post by mandville » Fri Oct 01, 2010 9:23 am

Hi
JSST had responded to you after your update request to say that it was unable to reproduce all the reports you submitted.
Please direct all comments to the JSST.
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

yehgnet
Joomla! Apprentice
Joomla! Apprentice
Posts: 21
Joined: Thu Dec 11, 2008 12:51 pm
Location: MM
Contact:

Re: Annoyed Delays From JSST

Post by yehgnet » Sat Oct 02, 2010 2:51 am

In response to the post
http://forum.joomla.org/viewtopic.php?f=432&t=553380 , which was meaninglessly locked,

Hi
JSST had responded to you after your update request to say that it was unable to reproduce all the reports you submitted.
Please direct all comments to the JSST.
How did you make sure JSST had responded to us?

JSST's response from JSST didn't come even to our SPAM box.

Ok, stayed tune.

We keep you posted with our proof-of-concept demo in both backend and front-end.
For this irresponsible-like unfriendly response case which wasted our time a lot, we will not notify you about vulnerabilities in coming 1.6 and future versions of 1.5.

Stay secure,
YGN Ethical Hacker Group
Last edited by ooffick on Sat Oct 09, 2010 4:15 pm, edited 1 time in total.
Reason: Mod Note: Removed manual Signature. Please read the Forum rules for details.

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Annoyed at delays from JSST

Post by mandville » Sat Oct 02, 2010 3:58 am

The topic was locked as you were asked to contact the JSST direct for an update on your reports.

<add>
I would also suggest you use one email address when contacting the JSST as all reports are connected to the email address of the reporter
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
ooffick
Joomla! Master
Joomla! Master
Posts: 11616
Joined: Thu Jul 17, 2008 3:10 pm
Location: Ireland
Contact:

Re: Annoyed at delays from JSST

Post by ooffick » Sat Oct 09, 2010 4:14 pm

Just a quick update on Wednesday October 6, 2010 a private message was sent to me and others apologizing for the previous report since it was mixup with an issue in an older version.

Olaf
Olaf Offick - Global Moderator
learnskills.org


Locked

Return to “Security in Joomla! 1.5”