Originally Posted by Hessah
|
Well if u're really considering to post it out in public.. ithink u should 1st wait and see if Outspark is planning to do anything about it..
have u worked out a way to stop this weakness?? have u told outspark wat they could possibly do? if u dont hv a solution for the problem u should wait longer
i personally dont recommend u (obviously) to post it in public coz that'll just ruin the whole thing for everyone... as it will be more than likely land in MANY bad hands...
a problem could probably be fixed without making it worst for everyone... it'll be very much appreciated if u dont take the dangerous approach.
just because one method "works" doesnt mean its the best way to deal with the problem.
|
Unfortunately, Hessah, thats not how companies think. If they believe its a localized problem, then from a corporate stand point its best just to brainwash your clientel, and give the appearance of no problems. In most cases you ignore the problem.
It's a business.
Companies respond to action. If everyone knows how to do it, they will be more pressed to fix it.
This security researcher Luigi Auriemma proved the concept works:
http://aluigi.altervista.org/
Furthermore, its not the job of a security researcher to fix the problem. Only point out the problem. None of us have the fiesta game code, the thing you need to be able to fix the problem.