I found a possible vulnerability and after reading info on the putty
site, it said the best way to let us know is by using an encrypted communications channel. I have no idea how to do that.
<skojohn8@gmail.com> wrote:
I found a possible vulnerability and after reading info on the putty
site, it said the best way to let us know is by using an encrypted communications channel. I have no idea how to do that.
At the moment, if you have a vulnerability to report in PuTTY, you'd
do best to report it through the HackerOne link in the news section on
the front page, because you can earn a bounty if it's a valid report.
Failing that, the usual approach is to send GPG-encrypted email to the development team, using the secure contact key on the Keys page of the
web site.
--
import hashlib; print((lambda p,q,g,y,r,s,m: (lambda w:(pow(g,int(hashlib.sha1(
m.encode('ascii')).hexdigest(),16)*w%q,p)*pow(y,r*w%q,p)%p)%q)(pow(s,q-2,q))==r
and m)(0xb80b5dacabab6145,0xf70027d345023,0x7643bc4018957897,0x11c2e5d9951130c9
,0xa54d9cbe4e8ab,0x746c50eaa1910, "Simon Tatham <anakin@pobox.com>" ))
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 403 |
Nodes: | 16 (2 / 14) |
Uptime: | 112:33:11 |
Calls: | 8,465 |
Calls today: | 2 |
Files: | 13,181 |
Messages: | 5,910,008 |