Anti-Phishing Research, Tombstones

Vulnerability Disclosure Policy, Coordinated Disclosure, Uncoordinated Disclosure, Hoyt LLC Research, XSS.CX Anti-Phishing Project

Updated Jan. 27, 2013
General Information
The XSS.Cx Web Crawler publishes Vulnerable Host reports into the Public Domain which are then indexed by Search Engines. 

Companies with external facing Vulnerability Management Programs then identify the XSS.CX Report, resolving the vulnerability in the normal course of business.
Additional Information as of 12-27-2011:
Hoyt LLC follows the Microsoft Coordinated Vulnerability Disclosure Policy at URL http://www.microsoft.com/security/msrc/report/disclosure.aspx


From time to time Full Disclosure may be used when a Vendor is unresponsive, slow to respond, stonewalling or not acting in the best interests of the community. 
Summary: Hoyt LLC Research respects the continuing need for Responsible Disclosure, but only to Responsible Parties.

No comments:

Post a Comment