MS security bugs

From: Paul Leach (paulleat_private)
Date: Tue Apr 27 1999 - 12:58:56 PDT

  • Next message: David LeBlanc: "Re: Bug in WinNT 4.0 SP4"

    Since some recent postings said they didn't know how to report bugs to
    Microsoft: please send reports of security bugs to "secureat_private".
    
    If you report a bug, you will initially get the following automated
    response:
    
    Thank you for your note to Secureat_private  Microsoft takes security
    very seriously, and we've developed this service to make it easy for
    customers to report potential security vulnerabilities in our products.  To
    help us better understand the issue that you're reporting, please make sure
    that you have provided as much detail as possible, including:
    
    - A complete description of the vulnerability, particularly what products
    are involved, how the vulnerability occurs, and what the security risk is.
    - Information that will allow us to reproduce the problem.  This should
    include a description of the scenario in which the problem occurs, and the
    version numbers of the products and operating system that you were using
    when you found the vulnerability. If you have applied any service packs or
    hotfixes, please tell us which ones. If the vulnerability involves a Web
    site, please give us its URL.
    - Your contact information, either an e-mail address or a phone number, in
    case an engineer needs to contact you for additional information.
    
    Unfortunately, we cannot provide technical support from this mailbox.  If
    you need help using a Microsoft product or have questions about a Microsoft
    Product, please see http://www.microsoft.com/support for information on the
    various types of technical support that are available.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:44:00 PDT