Re: SAP Security Contact

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Security@xxxxxxxxxxxxx goes to the police/traffic department at a certain northwest USA software company.
Secure@xxxxxxxxxxxxx is the proper alias for security bugs.

:-)

Nick Boyce wrote:
On 1/7/07, Nicob <nicob@xxxxxxxxx> wrote:

security@xxxxxxxxxx is the only standardized security contact (as
defined by RFC 2142)

While nobody could argue with that, I've lost count of the number of
banks and similar organisations to which I've tried to report phishing
scams via their "security@" alias, only to get a bounce saying no such
address.

And in at least one case (org name escapes me now) the "security@"
alias turned out to be a *physical* security department, populated by
large gentlemen with peaked caps and bulging armpits ... so you can't
rely on "security@".

Nick Boyce

--
Letting your vendors set your risk analysis these days? http://www.threatcode.com

If you are a SBSer and you don't subscribe to the SBS Blog... man ... I will hunt you down...
http://blogs.technet.com/sbs


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux