How to report a security bug w/o ADC account?

Hello! I did not find an approptiate forum, so i try here, i hope that's ok.
There is a security bug in some browsers, and Safari 2 suffers from it, too. The other vendors are already notified, but a cannot find a way to inform apple.
* It's an security issue, so i should notify Apple non-publicly before publishing
* It's in Safaris certificate handlig, so it's not in WebKit
* I do not have a MacOS system (with menu option +Report Bugs to Apple+ ) myself
* I won't accept tons of legal code to sign up to an ADC acount
* No, +Apple Care+ is not an option
I don't mind publishing the issue without notifying apple, but maybe apple does. ZB.

Well it looks like sending you here was a good thing.
I appreciate your concerns about open posting of any specific information; I am sure Apple and the other browser makers do too.
You might google on secunia and perhaps see if it's already known about. I did that for you.
http://secunia.com/
Good Luck, JP
Message was edited by: Jpfresno 'I did that...'

Similar Messages

  • How do I reset security question answers on my account?

    How do I reset security question answers on my account?

    1. See my User Tip for some help: Some Solutions for Resetting Forgotten Security Questions: Apple Support Communities.
    2. Here are two different but direct methods:
        a. Send Apple an email request at: Apple - Support - iTunes Store - Contact Us.
        b. Call Apple Support in your country: Customer Service: Contacting Apple for support
            and service.
    3. For other queries about Apple ID see Frequently asked questions about Apple ID.
    4. Rescue email address and how to reset Apple ID security questions

  • Invalid Signature (how to report a (potential) bug ) ?

    Hi,
    we have a PDF document signed via our IE browser (CAPICOM).
    When we open the document Acrobat (Professional) - version 8/9 - tells us the document has been modified since the signature was placed - which is of course not true.
    When we open this in another product (Nitro Reader) this product accepts the signatures and tells us the document is valid.
    We believe this could be a bug in Adobe Reader, so we can we open a "bug" report to get some help about this ?
    FYI: The /Sig dictiorant is as follows:
    /SubFilter /adbe.pkcs7.detached
    /Name (SERIALNUMBER=660...)
    /Filter /Adobe.PPKMS
    /M (D:20090302134456+01'00')
    /Type /Sig
    /ByteRange [00000000 00154554 00163772 00000444 ]
    /Contents <30820CAD06...>>
    H.

    Hi Leonard,
    The document we are having problems with is is a rather confidential one so I cannot publicly post it.
    If you send me your email address I can send it to you so you can have a look.
    We found out that with this document alone we had this issue.
    Attached ( http://www.speedyshare.com/918325897.html ) you'll find another example of a PDF document signed via IE/CAPICOM (signature coming from a cardreader).
    The CAPICOM has created a *detached* PKCS7 object but Adobe Reader refuses to validate it .
    If we generate a sha1 PKCS7 object with CAPICOM the Adobe Reader accepts the signature (valid).
    Any idea why ?
    Are there no tools which give more isight in the reason why ADobe invalidates the signature ?
    Looking forward to your response...
    H.

  • HT1689 How retrieve your lost security question for your iTunes account

    How retrieve a lost answer from your account question setting?

    Click here for information. If you forgot more than one answer and can't get them emailed to you for some reason(the email may take a few hours to arrive), contact the iTunes Store staff via the link in that article.
    (85446)

  • How to create a crystal report using secured web service as a datasource?

    Hi All Expert,
    I having some challenges on how to create a report using secured web service as a datasource in crystal report designer (CR11 R3).
    Secured Web Service including the certificate trusting, token authentication, header and/or body encryption. All web services running on https protocal.
    Could you please suggest me on the solution?
    Thank you and Best Regards,
    Cherr

    Please re-post if this is still an issue or purchase a case and have a dedicated support engineer work with you directly:
    http://store.businessobjects.com/store/bobjamer/DisplayProductByTypePage&parentCategoryID=&categoryID=11522300?resid=-Z5tUwoHAiwAAA8@NLgAAAAS&rests=1254701640551

  • How do I report a security problem to Firefox?

    Here's the problem: <br />
    Wednesday morning my Mac at home got infected by malware which I believe is usually called the "Google redirect virus". My Mac at home has been upgraded to OSX 10.6.7 and I believe I was using Firefox 3.6.13 (it automatically upgraded tonight). I haven't been able to find any useful information on line about this malware. <br />
    The behavior after infection was that every time I tried to use Google my request would get redirected. If I entered www.google.com in the address bar, the URL would get changed to www.google.com/FuneralHomes/<something> and the browser would try to go there and a "Under Construction" error message or a no-such-page message would be returned. This started happening after I did a Google search and was checking various links in Firefox, but once it started in Firefox I got the same behavior in Safari even without using Safari to look at any links. And it continued to happen in Safari even after I did a "Reset Safari..." <br />
    When I got infected I was using a non-adminstrator account and I was not asked to download anything nor was I prompted for a password. <br />
    I searched on "Google redirect Mac virus" using my (so far) untouched work computer and found several suggestions but no solutions. Apparently this is a PC problem that's been around a few years, but there were some Mac reports from last year. So last night I checked the DNS addresses in my
    Network preferences, looked at /etc/hosts, and removed the only plug-in from the Library:Internet Plug-ins of the infected account, even though it was a Picasa plug-in that predated this infection. None of those seemed to be the problem. I also scanned my disk with an up-to-date "Norton AntiVirus" which
    I got from work some time ago, but it found no viruses. <br />
    What really puzzles me is that the problem gradually went away while I was checking it last night. At first, when I entered www.google.com the browser would still show the redirected address in the prompt that comes up and it had the Legacy.com logo on the left instead of the Google one but it would actually go to the Google website (unless I'm being spoofed). Then at a later attempt, only the wrong logo persisted. Then at an even later attempt the logo got fixed and everything looked fine and appeared to behave correctly. <br />
    Frankly, that's a little scary. It's as if a really smart trojan got
    installed and was covering its tracks while it set up a man-in-the-middle attack (please advise if I'm misusing the jargon). If I'm being too paranoid, great, but I'd still like to know how such behavior could be induced on my machine just by linking to a website. Can anyone help?
    ''moderator- fixed the leading space formatting errors in this posting''

    Thanks, the-edmeister, but the only relevant post I found was from GB Colburn on bleepingcomputer.com, wherein he reported a similar problem about a year ago. I've found a few similar threads in the last year or so (by searching "Google redirect mac virus" in Google) but they are all about the same: someone reports the problem, responders have various random suggestions, the problem seems to go away by itself (at least sometimes), and there's nothing conclusive either good or bad.
    Without myself being as knowledgeable as GB Colburn, it doesn't look to me like the problem is in the DNS system or the router. It acts more like some malware in the automatic completion in the address bar of the browser or maybe in the history system, but I can't figure out how an infection in one browser could affect another browser. And I *really* can't figure out how it could be self-healing.
    It's really frustrating that none of the major parties involved in this—Firefox, Google, Safari (Apple), Verizon (my internet provider)—even have a process for reporting a security issue. At least not one that I, an ordinary semi-naive user, can find.

  • E1000g driver broken on solaris 10 u6; how to report this bug correctly?

    Question also posted in OpenSolaris forums:
    [http://www.opensolaris.org/jive/thread.jspa?messageID=329326]
    While upgrading a T2000 server to solaris 10 update 6 I found that my jumbo
    interfaces report errors on reboot.
    One frequent cause was that the update replaced /kernel/drv/e1000g.conf file
    (I changed the MaxFrameSize line to enable jumbo frames). This in-persistency
    of the file is annoying but well-known (bonus question: can I make changes to
    this file persistent?)
    However, the system still refused to set MTU = 9000 on the interfaces, and by
    default it assigns an MTU=8978 (instead of 16384 or 10244 as expected from
    other systems; we only need 9000 though). Googling showed that a few people
    have also discussed this regression.
    Copying in the driver file (/kernel/drv/sparcv9/e1000g) from Solaris 10 u4
    worked (network goes up, needed MTU is assigned). This doesn't seem like a
    suported and "enterprise" solution, so I want this bug to be known and fixed by
    Sun in the main tree.
    I haven't found any numbered bug report on this matter. How can I submit a bug
    for this regression in Solaris 10 (I couldn't reproduce the problem in OpenSolaris)?
    Can someone with access and skill please post the bug for us? :)
    e1000g driver module versions involved:
    sol10u4 (working): Intel PRO/1000 Ethernet 5.1.11
    sol10u6 (bad MTU limit): Intel PRO/1000 Ethernet 5.2.8
    //Jim Klimov

    Hello again, Mr. Cohen, and thank you for your corrections to my style.
    No offense taken, since it makes sense when you put it this way,
    and the point is taken - I'll try to be that specific next time. Thanks.
    Returning to the problem at hand, however with the abundance of
    Sun's tools to submit bugs (including those you pointed out above),
    I believed I might not know of some one more bugtracker.
    I also thought that "support cases" did differ from "bugs" which arise,
    taking my example, when Sun (or Intel?) took a working e1000g driver
    and "fixed" so it's no longer working - and then Sun releases it into
    the commercial version of the OS this way through all the presumed
    Q&A. And wants commercial users to pay for fixing it back. That's
    the part of the logic I found flawed somehow ;)
    So yes, you can say that I'm "cheap" to pay for Sun fixing something
    they broke themselves.
    I originally posted this report on OpenSolaris forum in hope someone
    would point out my misconfiguration or confirm that the problem exists
    for others.
    That forum (and/or the bugtracker search for keyword e1000g) also have
    a number of posts complaining about the vast number of ways this one
    e1000g driver was broken lately in 90s-100s OpenSolaris builds. Some
    posters even went as far as to suggest that someone reviews all works
    of the engineers and managers who are responsible for these recent
    flawed putpacks, or even provide some disciplinary action.
    I wouldn't go that far, but I was still saddened to find some other bug
    leak into the kinda-stable Solaris.
    //Jim on a mobile

  • How to report a bug in iTunes 11?

    How do I file a bug I found in iTunes 11?
    Basically, the bug is the following:
    1) Order albums by classification (stars).
    2) Go to the first album (with most stars), opening that "album view" (containing the songs) below the album
    3) Change the classification of some songs, so that the stars in this album won't make it be in the first place anymore. Nothing will change in the UI, the album will continue in first place.
    4) Click in any song of this same album.
    Result: a mess will happen. It will change the names of some musics and leave others, playing not the song you expect.

    There is a formal bug reporting site, but it is a lot of work.  For your purposes you're probably just as well off using the feedback links others provided.
    https://bugreport.apple.com/cgi-bin/WebObjects/RadarWeb.woa/wa/signIn

  • How do I make a bug report visible to others?

    I submitted a bug report and the conformation came back as follows:
    Your report has been assigned an internal review ID of: 164090
    This review ID is NOT visible on the "Java Developer Connection" (JDC).
    How do I make this bug report visible to others?

    You don't. The person dealing with it does if they reckon it's a real bug and worth bothering with.

  • How to find my submitted bug report in Java bug database

    I just submitted a bug report in Java bug database and it told me that the submission is successful without its bug ID and no email notification is received from Oracle.
    And I cannot find the bug in bug database with the title I submitted.
    The bug's product/category is Java Plug-in in JRE7
    So how could I get the bug status? Will it be fixed and how is it going on?

    I just submitted a bug report in Java bug database and it told me that the submission is successful without its bug ID and no email notification is received from Oracle.Last time I did that it also said it wouldn't appear straight away. They have to qualify bugs you know.
    And I cannot find the bug in bug database with the title I submitted.How long ago?
    So how could I get the bug status?Wait till it turns up?
    Will it be fixed and how is it going on?How would anyone on this forum know?

  • How to setup the security based on roles in Organization.

    Hi,
    How to setup the security based on roles in Organization.
    For example:Few users are Manager and a few user are Non Manager .Manager should have access to all work data including Non Manager and Non Manager should access based role.How to setup this? How OBI server identify the user role?
    kindly let me know.
    Regards.,
    CHR

    Hi,
    You need to have Back End support to achieve this. In Back End you need to create two groups . You need to know what joins has to be made for which group (which is more important) and also make session variable for the userrole (with SQL supporting it). In the BMM layer, we need to put the security join conditions in the 'where clause'.
    And make a common report. User loggin in with the respective userid will have userrole and joins assigned in the Back end. And they will be viewing the report according to their access.
    Hope this will solve your problem.
    Regards
    MuRam

  • Is this a security bug in Windows 8.1?

    I think I have discovered a serious security bug in Windows 8.1.
    Today I was using my (non-Admin) user account and with Internet Explorer I saved a file in the default Downloads folder (under This PC). The file was saved, but when I went to that folder, the file was not there! Now, I was about to downloaded
    it again, using IE, same as before, when I noticed in the Save dialog box that the file had indeed been downloaded, and that it was there, in the Downloads folder under This PC. Frustrated, I went to that very folder, but the file was nowhere
    to be found. I was really puzzled.
    Then, by chance, while logged in another account (namely the Admin account), I happened to go to the Downloads folder, and there was the file that I had downloaded using the other account.
    Obviously, what I described above represents a security problem: firstly because my private files may get saved by mistake into another person's account without me even realizing it, and secondly because I was able to access another person account
    (i.e. the Admin account) via the IE's Save dialog box, seeing the list of the files there, and possibly even accessing them (I have not tried the latter, though).
    Has anyone experienced anything like the situation I described?
    I must also say that I later tried to replicate this abnormal behavior, but for some unknown reason I couldn't. Anyway, I am sure that what I described above is an accurate account of how things went.

    Hi,
    Since I cannot repro your issue on my own computer, it cannot be a bug.
    I suggest we try to use another user account to see if there is the same issue happened.
    Please make sure your location of download folder is right:
    Right click Downloads folder, and choose Properties.
    Make sure the location is right under your user profile.
    If not, please click Location and click Restore default.
    If we still fail to solve you issue, please run Process monitor at the end of the downloading process to capture the actions, and upload the save log here for further research.
    You can also check if there is any weird actions at the end of downloading process.
    Process Monitor v3.05
    http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx
    How to use, please refer to this article:
    Using Process Monitor to capture system events
    http://www.sophos.com/en-us/support/knowledgebase/119038.aspx
    Keep post.
    Kate Li
    TechNet Community Support

  • How to report a problem in ios 7

    i have found a minot glitch in iphone ios 7... related to the lock screen, how to report it to apple and is it true that if i found a bug i get paid for it ?

    No, you do not get paid for reporting bugs.  You can submit feedback here:
    http://www.apple.com/feedback
    Perhaps if you described the problem here, someone could help you with it.

  • How to report employee thief to adobe, safe harbor, and your partners, there is no email, no phone,

    how to report employee thief to adobe, safe harbor, and your partners, there is no email, no phone, spent 1 hr 26 min with Adobe support, and after I gave him permission to access my computer, I had to ask him if he was having a problem, than I receive a security notice that the software program is not from a confirmed web site and was downloaded to an unknown web address, when I asked the support
    person if this was the program, I did not see https or a lock and he sail it was ok it was him.
    I notice he had deleted some files and was in process of changing my security logins files and change wifi and proxy, when I tried to stop him he locked my mouse so I had to power off computer. after that there was a virus installed on my computer,
    I have spent the last 3 hrs getting a different virus protection software to clean my Hard drive.
    I want this guy fired,
    Funny I have been trying to get in touch with adobe since March 29,2015, no emails and when I got someone one the phone he could not under stand me, but I can understand why since he could
    not speak english, WOW Great support ADOBE.
    I bet I will get there attn. now.
    anyone have another way to contact this great company?

    I am unable to get the numbers about the first imd I contacted adobe, but was able to get the chat records if that would help, my computer is fried, I have been spending last 2 days trying to remove the virus and ad wares, I have been told looked like I will have to erase the drive an install every thing from scratch

  • How to reset my security question in itunes

    how to reset my security question in itunes

    Frequently asked questions about Apple ID - http://support.apple.com/kb/HE37 --> Can I change the answers to the security questions for my Apple ID?  --> Yes. You can change the answers to the security questions provided when you originally signed up for your Apple ID. Go to My Apple ID (http://appleid.apple.com/) and click Manage your account.
    Forgotten security questions - https://discussions.apple.com/message/18402551  and https://discussions.apple.com/message/18625296
    More involved forgotten question issues - https://discussions.apple.com/thread/3961813
    Kappy 09/2012 post about security questions - https://discussions.apple.com/message/19569468
    John Galt's tips (09&11/2012) - https://discussions.apple.com/message/19809294 and https://discussions.apple.com/message/20229239
    If none of the above work, contact iTunes Support at http://www.apple.com/support/itunes/contact/ and follow the instructions to report the issue to the iTunes Store.

Maybe you are looking for

  • How do I create email address groups in Mail?

    I want to be able to click on a group of addresses already created for specific topics. For example, out of my entire address book, one group would be for work, another for church and another for just family and friends. Can this be done. I get tired

  • Arabic Language

    I recently purchased Xperia Z2... but i am having problem in changing the language to ARABIC as there is no arabic lanugage installed in the phone it seems... is there any way to install language pack... i can type in arabic but phone lanugage is not

  • Apple TV vs. Netflicks

    So I'm trying decide whether to get the apple tv or the netflicks movie streaming device. The largest fact keeping me from going with the atv is that you must pay like 3.99 for each movie while netflicks offers a subscription starting at 8.99 a month

  • HTML for Mobile

    Hey Gang, I've seen a few retialers adding links to their HTML email promotions saying "To view this on your PDA click here" Which basically takes them to an HTML page designed and developed to fit in a PDS screen. Using device central (great tool in

  • Plugin check page says I need to update Google Earth, but the link doesn't work.

    This question came up before. Pineman gave a useful link. I went there. I was told that I have the plug-in version 6.1.0.5001 installed. Isn't that the latest? If so, why doesn't Firefox know that?