<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns:p="urn:schemas-microsoft-com:office:powerpoint" xmlns:a="urn:schemas-microsoft-com:office:access" xmlns:dt="uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s="uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs="urn:schemas-microsoft-com:rowset" xmlns:z="#RowsetSchema" xmlns:b="urn:schemas-microsoft-com:office:publisher" xmlns:ss="urn:schemas-microsoft-com:office:spreadsheet" xmlns:c="urn:schemas-microsoft-com:office:component:spreadsheet" xmlns:odc="urn:schemas-microsoft-com:office:odc" xmlns:oa="urn:schemas-microsoft-com:office:activation" xmlns:html="http://www.w3.org/TR/REC-html40" xmlns:q="http://schemas.xmlsoap.org/soap/envelope/" xmlns:rtc="http://microsoft.com/officenet/conferencing" xmlns:D="DAV:" xmlns:Repl="http://schemas.microsoft.com/repl/" xmlns:mt="http://schemas.microsoft.com/sharepoint/soap/meetings/" xmlns:x2="http://schemas.microsoft.com/office/excel/2003/xml" xmlns:ppda="http://www.passport.com/NameSpace.xsd" xmlns:ois="http://schemas.microsoft.com/sharepoint/soap/ois/" xmlns:dir="http://schemas.microsoft.com/sharepoint/soap/directory/" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:dsp="http://schemas.microsoft.com/sharepoint/dsp" xmlns:udc="http://schemas.microsoft.com/data/udc" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:sub="http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/" xmlns:ec="http://www.w3.org/2001/04/xmlenc#" xmlns:sp="http://schemas.microsoft.com/sharepoint/" xmlns:sps="http://schemas.microsoft.com/sharepoint/soap/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:udcs="http://schemas.microsoft.com/data/udc/soap" xmlns:udcxf="http://schemas.microsoft.com/data/udc/xmlfile" xmlns:udcp2p="http://schemas.microsoft.com/data/udc/parttopart" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns:st="" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
span.EmailStyle21
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle22
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle23
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
        {page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="2050" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=EN-US link=blue vlink=purple>
<div class=Section1>
<p class=MsoNormal><span style='color:#1F497D'>I am not suggesting exposing
zero days. I only want known vulnerabilities in applications like web goat
etc that are known to everyone. I don’t even plan on naming where each
vulnerability comes from but rather instead change the code to protect the
innocent. I would never encourage promoting sharing zero days. I hope this
clears it up. <o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>Thanks,<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>Matt<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<div>
<p class=MsoNormal><span style='color:#1F497D'>Matt Parsons, MSM, CISSP<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>315-559-3588 Blackberry<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>817-294-3789 Home office <o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>"Do Good and Fear No
Man" <o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>Fort Worth, Texas<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>A.K.A The Keyboard Cowboy<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><a
href="mailto:mparsons1980@gmail.com"><span style='color:blue'>mailto:mparsons1980@gmail.com</span></a><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><a
href="http://www.parsonsisconsulting.com"><span style='color:blue'>http://www.parsonsisconsulting.com</span></a><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><a
href="http://www.o2-ounceopen.com/o2-power-users/"><span style='color:blue'>http://www.o2-ounceopen.com/o2-power-users/</span></a><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><a
href="http://www.linkedin.com/in/parsonsconsulting"><span style='color:blue'>http://www.linkedin.com/in/parsonsconsulting</span></a><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><a
href="http://parsonsisconsulting.blogspot.com/"><span style='color:blue'>http://parsonsisconsulting.blogspot.com/</span></a><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><a
href="http://www.vimeo.com/8939668"><span style='color:blue'>http://www.vimeo.com/8939668</span></a><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><img border=0 width=80
height=90 id="_x0000_i1029" src="cid:image003.jpg@01CAC518.3D9C7070"
alt="0_0_0_0_250_281_csupload_6117291"><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><img border=0 width=75
height=75 id="_x0000_i1028" src="cid:image004.jpg@01CAC518.3D9C7070"
alt=untitled><o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'> <o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'> <o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'> <o:p></o:p></span></p>
</div>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<div>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'>
<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> Arshan Dabirsiaghi
[mailto:arshan.dabirsiaghi@aspectsecurity.com] <br>
<b>Sent:</b> Tuesday, March 16, 2010 2:49 PM<br>
<b>To:</b> McGovern, James F. (P+C Technology); Matt Parsons;
OWASPDallas@utdallas.edu<br>
<b>Cc:</b> websecurity@webappsec.org; SC-L@securecoding.org<br>
<b>Subject:</b> RE: [WEB SECURITY] RE: [SC-L] blog post and open source
vulnerabilities to blog about<o:p></o:p></span></p>
</div>
</div>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><span style='color:#1F497D'>I’m not sure Matt was suggesting
<s>burning</s> sharing 0days, but if he was, I think he should not be
discouraged. I think disclosure preference should be something like a
“protected class” within OWASP.<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'>Arshan<o:p></o:p></span></p>
<p class=MsoNormal><span style='color:#1F497D'><o:p> </o:p></span></p>
<div>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'>
<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> McGovern, James F.
(P+C Technology) [mailto:James.McGovern@thehartford.com] <br>
<b>Sent:</b> Tuesday, March 16, 2010 2:36 PM<br>
<b>To:</b> Matt Parsons; OWASPDallas@utdallas.edu<br>
<b>Cc:</b> websecurity@webappsec.org; SC-L@securecoding.org<br>
<b>Subject:</b> [WEB SECURITY] RE: [SC-L] blog post and open source
vulnerabilities to blog about<o:p></o:p></span></p>
</div>
</div>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><span style='font-size:10.0pt;font-family:"Arial","sans-serif";
color:blue'>This doesn't feel like responsible disclosure and is not the way to
announce weaknesses in software. It is best to deal with scenarios that have
already been addressed. </span><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p> </o:p></span></p>
<div class=MsoNormal align=center style='text-align:center'><span
style='font-size:12.0pt;font-family:"Times New Roman","serif"'>
<hr size=2 width="100%" align=center>
</span></div>
<p class=MsoNormal style='margin-bottom:12.0pt'><b><span style='font-size:10.0pt;
font-family:"Tahoma","sans-serif"'>From:</span></b><span style='font-size:10.0pt;
font-family:"Tahoma","sans-serif"'> sc-l-bounces@securecoding.org
[mailto:sc-l-bounces@securecoding.org] <b>On Behalf Of </b>Matt Parsons<br>
<b>Sent:</b> Tuesday, March 16, 2010 11:41 AM<br>
<b>To:</b> OWASPDallas@utdallas.edu<br>
<b>Cc:</b> websecurity@webappsec.org; SC-L@securecoding.org<br>
<b>Subject:</b> [SC-L] blog post and open source vulnerabilities to blog about</span><span
style='font-size:12.0pt;font-family:"Times New Roman","serif"'><o:p></o:p></span></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal>Hello,<o:p></o:p></p>
<p class=MsoNormal>I am working on a software security blog and I am trying to
find open source vulnerabilities to present and share. Does anyone else
have any open source vulnerabilities that they could share and talk
about? I think this could be the best way to learn in the open
source community about security. I have a few but I would like to
blog about a different piece of code almost every day. <o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal>God Bless.<br>
Matt<o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><a href="http://parsonsisconsulting.blogspot.com/">http://parsonsisconsulting.blogspot.com/</a><o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal>Matt Parsons, MSM, CISSP<o:p></o:p></p>
<p class=MsoNormal>315-559-3588 Blackberry<o:p></o:p></p>
<p class=MsoNormal>817-294-3789 Home office <o:p></o:p></p>
<p class=MsoNormal>"Do Good and Fear No Man" <o:p></o:p></p>
<p class=MsoNormal>Fort Worth, Texas<o:p></o:p></p>
<p class=MsoNormal>A.K.A The Keyboard Cowboy<o:p></o:p></p>
<p class=MsoNormal><a href="mailto:mparsons1980@gmail.com">mailto:mparsons1980@gmail.com</a><o:p></o:p></p>
<p class=MsoNormal><a href="http://www.parsonsisconsulting.com">http://www.parsonsisconsulting.com</a><o:p></o:p></p>
<p class=MsoNormal><a href="http://www.o2-ounceopen.com/o2-power-users/">http://www.o2-ounceopen.com/o2-power-users/</a><o:p></o:p></p>
<p class=MsoNormal><a href="http://www.linkedin.com/in/parsonsconsulting">http://www.linkedin.com/in/parsonsconsulting</a><o:p></o:p></p>
<p class=MsoNormal><a href="http://parsonsisconsulting.blogspot.com/">http://parsonsisconsulting.blogspot.com/</a><o:p></o:p></p>
<p class=MsoNormal><a href="http://www.vimeo.com/8939668">http://www.vimeo.com/8939668</a><o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><img border=0 width=80 height=90 id="Picture_x0020_1"
src="cid:image005.jpg@01CAC518.3D9C7070" alt="0_0_0_0_250_281_csupload_6117291"><o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><img border=0 width=75 height=75 id="Picture_x0020_2"
src="cid:image006.jpg@01CAC518.3D9C7070" alt=untitled><o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal> <o:p></o:p></p>
<p class=MsoNormal> <o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal> <o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<pre>************************************************************<o:p></o:p></pre><pre>This communication, including attachments, is for the exclusive use of addressee and may contain proprietary, confidential and/or privileged information. If you are not the intended recipient, any use, copying, disclosure, dissemination or distribution is strictly prohibited. If you are not the intended recipient, please notify the sender immediately by return e-mail, delete this communication and destroy all copies.<o:p></o:p></pre><pre>************************************************************<o:p></o:p></pre></div>
</body>
</html>