I'd have to agree with the eEye statement on this one. You sent out an advisory without disclosing the details, which offers no real benefit to anyone. Many people consider this responsible disclosure but that also requires you to notify the vendor (there were no @eeye.com's in your "to" list but there were a couple of press mailboxes).
Paul Schmehl (pauls@xxxxxxxxxxxx) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html