Reporting a Security Bug

Jaybird180

Final Approach
Joined
Dec 28, 2010
Messages
9,034
Location
Near DC
Display Name

Display name:
Jaybird180
About a year ago, I found a non-repudiation related flaw in a Microsoft product. At the time I thought, ok that's cool but has little practical value. This morning, I re-discovered the flaw and a practical application. I've never reported security issues before and found out about connect.microsoft.com from a Google search.

1- I think MS should fix the problem.
2- I want the credit for discovering and reporting it

I took a screen shot of the "About" box and removed the license key (because it is a Gov't license -not sure how that would pan out legally)

How do I go about doing this? More importantly, I want to do this in a way that is legally safe for me. I've already done a write-up description of it with the screenshot and the steps to duplicate.

Suggestions?
 
Give them no warning and publish at BlackHat next year. Seems to be popular with all the cool kids. LOL!
 
Back
Top