PageSourceSearch

https://insecure.org/news/fulldisclosure/

html insecure.org collected 2026-10-01 11:25:38 UTC 10,915 bytes, 180 lines download raw bytes

1<HTML>
2<HEAD>
3<TITLE>Full Disclosure Mailing List: A Fresh Start</TITLE>
4<META name="description" content="Seclists.org is pleased to offer a fresh start to the wonderful Full Disclosure Mailing List">
5
6<meta name="viewport" content="width=device-width,initial-scale=1">
7<meta name="theme-color" content="#2A0D45">
8<link rel="preload" as="image" href="/images/sitelogo.png" imagesizes="168px" imagesrcset="/images/sitelogo.png, /images/sitelogo-2x.png 2x">
9<link rel="preload" as="image" href="/shared/images/nst-icons.svg">
10<link rel="stylesheet" href="/shared/css/nst.css?v=2">
11<script async src="/shared/js/nst.js?v=2"></script>
11
12<link rel="stylesheet" href="/shared/css/nst-foot.css?v=2" media="print" onload="this.media='all'">
13<link rel="stylesheet" href="/site.css">
14<!--Google Analytics Code-->
15<link rel="preload" href="https://www.google-analytics.com/analytics.js" as="script">
16<script>
vendor: 328 bytes, lines 16-21
16
17(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
18(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
19m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
20})(window,document,'script','//www.google-analytics.com/analytics.js','ga');
21ga('create', '
21UA-11009417-1
vendor: 36 bytes, lines 21-22
21', 'auto');
22ga('send', 'pageview');
23</script>
23
24<!--END Google Analytics Code-->
25<META NAME="ROBOTS" CONTENT="NOARCHIVE">
26<link rel="shortcut icon" href="/shared/images/tiny-eyeicon.png" type="image/png">
27</head>
28<body><div id="nst-wrapper">
29
30<div id="menu">
31 <div class="blur">
32  <header id="nst-head">
33
34    <a id="menu-open" href="#menu" aria-label="Open menu">
35     <img width="44" height="44" alt="" aria-hidden="true"
36      src="/shared/images/nst-icons.svg#menu">
37    </a>
38    <a id="menu-close" href="#" aria-label="Close menu">
39     <img width="44" height="44" alt="" aria-hidden="true"
40      src="/shared/images/nst-icons.svg#close">
41    </a>
42
43   <a id="nst-logo" href="/" aria-label="Home page">
44    <img alt="Home page logo" srcset="/images/sitelogo.png, /images/sitelogo-2x.png 2x" src="/images/sitelogo.png" onerror="this.onerror=null;this.srcset=this.src" height=90 width=168></a>
45
46   <nav id="nst-gnav">
47    <a class="nlink" href="https://nmap.org/">Nmap.org</a>
48    <a class="nlink" href="https://npcap.com/">Npcap.com</a>
49    <a class="nlink" href="https://seclists.org/">Seclists.org</a>
50    <a class="nlink" href="https://sectools.org">Sectools.org</a>
51    <a class="nlink" href="https://insecure.org/">Insecure.org</a>
52   </nav>
53
54   <form class="nst-search" id="nst-head-search" action="/search/">
55    <input class="nst-search-q" name="q" type="search" placeholder="Site Search">
56    <button class="nst-search-button" title="Search">
57     <img style="width:100%;aspect-ratio:1/1;" alt="" aria-hidden="true"
58      src="/shared/images/nst-icons.svg#search">
59     </button>
60   </form>
61
62  </header>
63 </div>
64</div>
65
66<main id="nst-content">
67
68
69<center>
70<img src="https://seclists.org/images/fulldisclosure-logo.png" width=80 height=40>
71<br><font size="+2"><b>Full Disclosure Mailing List: A Fresh Start</b></font><br>
72March 25, 2014
73</center>
74
75
76<P>Like many of us in the security community, I (<a href="http://insecure.org/fyodor/">Fyodor</a>) was shocked last week by John Cartwright's <a href="http://seclists.org/fulldisclosure/2014/Mar/332">abrupt termination</a> of the Full Disclosure list which he and Len Rose created way back in July 2002.  It was a great 12-year run, with <a href="http://seclists.org/fulldisclosure/">more than 91,500 posts</a> during John's tenure.  During that time he fought off numerous trolls, DoS attacks, spammers, and legal threats from angry vendors and researchers alike.  John truly deserves our appreciation and thanks for sticking with it so long!
77
78<P>Some have argued that we no longer need a Full Disclosure list, or even that mailing lists as a concept are obsolete.  They say researchers should just Tweet out links to advisories that can be hosted on Pastebin or company sites.  I disagree.  Mailing lists create a much more permanent record and their decentralized nature makes them harder to censor or quietly alter in the future.  Jericho from OSVDB and Attrition <a href="http://blog.osvdb.org/2014/03/19/missing-perspective-on-the-closure-of-the-full-disclosure-mail-list/">elaborates further in this great post</a>.
79
80<P>Upon hearing the bad news, I immediately wrote to John offering help.  He said he was through with the list, but suggested: &ldquo;you don't need me.  If you want to start a replacement, go for it.&rdquo;  After some soul searching about how much I personally miss the list (despite all its flaws), I've decided to do so!  I'm already quite familiar with handling legal threats and removal demands (usually by ignoring them) since I run <a href="http://seclists.org">Seclists.org</a>, which has long been the most popular archive for Full Disclosure and many other great security lists.  I already maintain mail servers and Mailman software because I run various other large lists including <a href="http://seclists.org/nmap-dev/">Nmap Dev</a> and <a href="http://seclists.org/nmap-announce/">Nmap Announce</a>.
81
82<P>The new list must be run by and for the security community in a vendor-neutral fashion.  It will be lightly moderated like the old list, and a volunteer moderation team will be chosen from the active users.  As before, this will be a public forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. FD differs from other security lists in its open nature, light (versus restrictive) moderation, and support for researchers' right to decide how to disclose the
82ir own discovered bugs. The <a href="http://en.wikipedia.org/wiki/Full_disclosure">full disclosure movement</a> has been credited with forcing vendors to better secure their products and to publicly acknowledge and fix flaws rather than hide them. Vendor legal intimidation and censorship attempts won't be tolerated!
83
84<P>This list is taking a fresh start (rather than importing the old Full Disclosure member addresses), so you need to manually subscribe if you wish to be a member.  Here is a handy form for doing so:
85
86<P><center>
87<FORM Method=POST ACTION="http://nmap.org/mailman/subscribe/fulldisclosure">
88<INPUT type="Text" name="email" size="25" value="">
89<font color="#000000"><INPUT type="Submit" name="email-button" value="Subscribe to Full Disclosure"></font><BR>
90(or subscribe with custom options from the <a href="http://nmap.org/mailman/listinfo/fulldisclosure">Full Disclosure Mailman list info page</a>)
91</FORM>
92</center>
93
94<P>Thanks for joining, and I will try my best to manage this list as well and hopefully for as long as John's epic tenure!  Once you subscribe using the box above or the <a href="http://nmap.org/mailman/listinfo/fulldisclosure">Mailman page</a>, you should receive a confirmation email.  Perform the confirmation steps (web or email) and you should receive a welcome email confirming that you are subscribed.
95
96<p>This is meant to be a community resource, so if you have any suggestions or questions, please post them to the list.  You can also email me directly at <a href="mailto:[email protected]">[email protected]</a>.
97
98<BR><BR>-<a href="http://insecure.org/fyodor/">Fyodor</a>
99
100<BR><BR>
101</main><!-- content -->
102
103<footer id="nst-foot">
104   <form class="nst-search" id="nst-foot-search" action="/search/">
105    <input class="nst-search-q" name="q" type="search" placeholder="Site Search">
106    <button class="nst-search-button" title="Search">
107     <img style="width:100%;aspect-ratio:1/1;" alt="" aria-hidden="true"
108      src="/shared/images/nst-icons.svg#search">
109     </button>
110   </form>
111<div class="flexlists">
112<div class="fl-unit">
113<h2><a class="nlink" href="https://nmap.org/">Nmap Security Scanner</a></h2>
114<ul>
115<li><a class="nlink" href="https://nmap.org/book/man.html">Ref Guide</a>
116<li><a class="nlink" href="https://nmap.org/book/install.html">Install Guide</a>
117<li><a class="nlink" href="https://nmap.org/docs.html">Docs</a>
118<li><a class="nlink" href="https://nmap.org/download.html">Download</a>
119<li><a class="nlink" href="https://nmap.org/oem/">Nmap OEM</a>
120</ul>
121</div>
122<div class="fl-unit">
123<h2><a class="nlink" href="https://npcap.com/">Npcap packet capture</a></h2>
124<ul>
125<li><a class="nlink" href="https://npcap.com/guide/">User's Guide</a>
126<li><a class="nlink" href="https://npcap.com/guide/npcap-devguide.html#npcap-api">API docs</a>
127<li><a class="nlink" href="https://npcap.com/#download">Download</a>
128<li><a class="nlink" href="https://npcap.com/oem/">Npcap OEM</a>
129</ul>
130</div>
131<div class="fl-unit">
132<h2><a class="nlink" href="https://seclists.org/">Security Lists</a></h2>
133<ul>
134<li><a class="nlink" href="https://seclists.org/nmap-announce/">Nmap Announce</a>
135<li><a class="nlink" href="https://seclists.org/nmap-dev/">Nmap Dev</a>
136<li><a class="nlink" href="https://seclists.org/fulldisclosure/">Full Disclosure</a>
137<li><a class="nlink" href="https://seclists.org/oss-sec/">Open Source Security</a>
138<li><a class="nlink" href="https://seclists.org/dataloss/">BreachExchange</a>
139</ul>
140</div>
141<div class="fl-unit">
142<h2><a class="nlink" href="https://sectools.org">Security Tools</a></h2>
143<ul>
144<li><a class="nlink" href="https://sectools.org/tag/vuln-scanners/">Vuln scanners</a>
145<li><a class="nlink" href="https://sectools.org/tag/pass-audit/">Password audit</a>
146<li><a class="nlink" href="https://sectools.org/tag/web-scanners/">Web scanners</a>
147<li><a class="nlink" href="https://sectools.org/tag/wireless/">Wireless</a>
148<li><a class="nlink" href="https://sectools.org/tag/sploits/">Exploitation</a>
149</ul>
150</div>
151<div class="fl-unit">
152<h2><a class="nlink" href="https://insecure.org/">About</a></h2>
153<ul>
154<li><a class="nlink" href="https://insecure.org/fyodor/">About/Contact</a>
155<li><a class="nlink" href="https://insecure.org/privacy.html">Privacy</a>
156<li><a class="nlink" href="https://insecure.org/advertising.html">Advertising</a>
157<li><a class="nlink" href="https://nmap.org/npsl/">Nmap Public Source License</a>
158</ul>
159</div>
160<div class="fl-unit social-links">
161<a class="nlink" href="https://twitter.com/nmap" title="Visit us on Twitter">
162 <img width="32" height="32" src="/shared/images/nst-icons.svg#twitter" alt="" aria-hidden="true">
163 </a>
164<a class="nlink" href="https://facebook.com/nmap" title="Visit us on Facebook">
165 <img width="32" height="32" src="/shared/images/nst-icons.svg#facebook" alt="" aria-hidden="true">
166 </a>
167<a class="nlink" href="https://github.com/nmap/" title="Visit us on Github">
168 <img width="32" height="32" src="/shared/images/nst-icons.svg#github" alt="" aria-hidden="true">
169 </a>
170<a class="nlink" href="https://reddit.com/r/nmap/" title="Discuss Nmap on Reddit">
171 <img width="32" height="32" src="/shared/images/nst-icons.svg#reddit" alt="" aria-hidden="true">
172 </a>
173</div>
174</div>
175</footer>
176
177</div><!-- wrapper -->
178</body>
179</html>
180

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.