Netscape Responds To Hacker's Claims

Tags: Netscape + Digg + Hack + Alex Rudloff

Rasti
Rasti posted on Aug 8th 2006 5:01PM; via securitypronews.com/news/secur...
Netscape Responds To Hacker's Claims

The hacker that cracked Netscape's cross-site scripting (XSS) vulnerability and used it to deface the company's answer to Digg.com maintains that he tried incessantly to contact Netscape about the problem to warn them before hand. Netscape thinks he didn't try hard enough.

"Luckily for us, we already had code on the way out the door to address this and similar possibilities. The matter was resolved in hours, if not minutes," he said. " We work hard, we work late -- but there are a ton of script kiddies in the world."

Rudloff denied that Netscape had ignored repeated warnings, but didn't speak specifically to one instance.

"A number of people, internal and external, have forwarded me XSS warnings and were responded to," he said. "There is rarely anything sent in that isn't sent in by a dozen other people, especially oversights like XSS."

"We do our best to read everything that comes our way and we respond where we can. There are 4 developers yet thousands of e-mails."

He said any hacker could easily get into contact with the Netscape developer team via email and instant messenger through a simple Google search.

"We're extremely transparent and open. Posting vague story submissions that get buried quickly by the community and/or anchors is probably the least effective way to do it though."

   0 votes | Bookmark

Comments

Guest

Alex Rudloff says:

Or maybe he did, who knows -- my point is that we get thousands of e-mails a day, most of it is noise and/or dupes. It's frustrating when it's painted as a situation of us making a conscious choice to ignore these types of things. That's just not the case, ya know?

The entire team is extremely reachable online. If someone feels they're being ignored or their e-mail didn't make it, just shoot us a message via the profile or im. It's a heck of a lot easier on everyone

In whatever scenerio, it is our fault and our responsibility. All we can do is apologize to those affected, clean up and make sure it doesn't happen again.

Anyway... Just my two cents
Posted: 08/17/06 00:01

Rasti

Rasti says:

Luckily nothing malicious has been done and the users aren’t at risk.
Posted: 08/17/06 01:39

Add your comment here

Enter the text you see on the right 



Popular Tags


Popular Members


Related Posts

Other Gates you might be interested in:

More Gates