Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CALx_OUAW0kFGi5ZcX6K_5tjcTHCpQWfh+RK2kqXEzmhuUhwDMQ@mail.gmail.com>
Date: Mon, 6 Oct 2014 20:33:44 -0700
From: Michal Zalewski <lcamtuf@...edump.cx>
To: oss-security <oss-security@...ts.openwall.com>
Subject: Re: Who named shellshock?

This is the bit from Stephane:

http://www.openwall.com/lists/oss-security/2014/10/03/14

-- snip! --
A release schedule with public disclosure on the 24th at
14:00 UTC and early notification to other unix and linux
vendors on the 22nd and select infrastructure provider
notification (such as CDNs including Microsoft) on the 23rd
proposed on the 16th by Florian.

[...]

bashdoor.com was registered (not by me) with a creation date of
2014-09-24 13:59 UTC sometime before 2014-09-24 06:59:10Z
according to whois. Florian also said here that someone brought
the early notification sent to vendors/infrastructure to the
press, so someone obviously intended to take it to the press. I
don't know whom.
-- snip! --

The bashdoor.com thing sounds a bit damning (doesn't sound like
something that would be in the notifications to CDNs & co?).

/mz

On Mon, Oct 6, 2014 at 7:28 PM, Solar Designer <solar@...nwall.com> wrote:
> Florian,
>
> On Mon, Oct 06, 2014 at 02:04:42PM -0700, Michal Zalewski wrote:
>> I don't think it happened on Twitter - using advanced search with date
>> ranges, I don't see any mentions that would predate this article,
>> which already seems to be using the term:
>>
>> http://www.csoonline.com/article/2687265/application-security/remote-exploit-in-bash-cve-2014-6271.html
>>
>> It's odd that an article posted at 8 AM on Sept 24 would have any idea
>> of how the bug is already being called by the security community,
>> especially ahead of any Twitter buzz. But both Stephane and Florian
>> implied that some of the pre-notified parties apparently started
>> leaking details to the press and were getting ready to make a splash
>> the moment it goes public, so maybe that's the explanation.
>
> I don't know who coined the Shellshock name, but I'd like us to know
> whether there was in fact a leak, and when.  (Luckily, I know it
> couldn't have been from the distros list, because no detail was posted
> to the distros list, thanks!)  I had raised this concern here:
>
> http://www.openwall.com/lists/oss-security/2014/09/24/36
>
> It is insufficient that "it was an honest mistake" and that "apologies
> were made and accepted."
>
> I have no intent to place blame, but at least the general public needs
> to know whether the information got to the press before or after the
> scheduled coordinated public disclosure date/time ("Wednesday,
> 2014-09-24 14:00 UTC").  If it's before, then this qualifies as a leak.
> If it's after, then it does not.
>
> The article has "Sep 24, 2014 8:35 AM PT" on it, which is 15:35 UTC.
> Did the article's author receive the information before or after 14:00,
> and when exactly?
>
> NB: Please do not provide any information on this to me in private.
> If you're able to address my question, please do so on the list.
>
> Thanks,
>
> Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.