Disclosure-for-pay?

From: Talley, Brooks (brooksat_private)
Date: Wed Jul 16 2003 - 14:01:51 PDT

  • Next message: Mandrake Linux Security Team: "MDKSA-2003:074 - Updated kernel packages fix multiple vulnerabilities"

    My company recently received a communication from someone purporting to
    know of a security vulnerability in our web application. The individual
    stated that they would sign an NDA and report the details of the
    vulnerability to us if we paid his "consulting fee" and provided future
    services to him at no cost.
    
    Am I crazy here, or does this sound not good in several different ways?
    
    Is that kind of demand for payment for reporting a vulnerability at all
    the norm?
    
    I'd love any advice here.
    
    Thanks
    -Brooks
    



    This archive was generated by hypermail 2b30 : Wed Jul 16 2003 - 15:19:17 PDT