Re: Vulnerability Report (DMARC RECORD)

From: "M(dot)Arslan Kabeer" <arslan(dot)whitehat(at)inbox(dot)eu>
To: "Magnus Hagander" <magnus(at)hagander(dot)net>
Cc: "PostgreSQL WWW" <pgsql-www(at)postgresql(dot)org>
Subject: Re: Vulnerability Report (DMARC RECORD)
Date: 2021-04-21 21:31:00
Message-ID: 1619040660.60809994b4e19@mail.inbox.eu
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

<html>I have found the vulnerability in&nbsp;hagander.net&nbsp;and It was my moral obligation to report it to them.
<div class="noTransl">----- Reply to message -----<br />
<b>Subject: </b>Re: Vulnerability Report (DMARC RECORD)<br />
<b>Date: </b>Fri, 16 Apr 2021, 13:11<br />
<b>From: </b> Magnus Hagander <a href="mailto:magnus(at)hagander(dot)net">&lt;magnus(at)hagander(dot)net&gt;</a><br />
<b>To: </b> <a href="mailto:arslan(dot)whitehat(at)inbox(dot)eu">&lt;arslan(dot)whitehat(at)inbox(dot)eu&gt;</a></div>

<blockquote>On Fri, Apr 16, 2021 at 12:05 PM &lt;arslan(dot)whitehat(at)inbox(dot)eu&gt; wrote:<br />
&gt;<br />
&gt; Hello Team,<br />
&gt; I am a security researcher and I founded this vulnerability in your website.<br />
<br />
First of all, this is not a vulnerability.<br />
Second, this is not about a website, it&#39;s about email.<br />
<br />
<br />
<br />
&gt; Hoping for the bounty for my ethical Disclosure.<br />
<br />
Please note that<br />
<br />
1. The PostgreSQL open source project does not have a bug bounty<br />
program. Individual vendors may, but not the open source project.<br />
<br />
2. You announced your &quot;discovery&quot; publicly, that&#39;s not the normal way<br />
to get a bounty from *any* source. But luckily, it wasn&#39;t actually a<br />
vulnerability.<br />
<br />
<br />
//Magnus</blockquote>
</html>

Attachment Content-Type Size
unknown_filename text/html 1.3 KB

In response to

Browse pgsql-www by date

  From Date Subject
Next Message David Turoň 2021-04-23 05:36:18 Wiki editor request
Previous Message Magnus Hagander 2021-04-16 10:10:58 Re: Vulnerability Report (DMARC RECORD)