Marc wrote:
> [....]
> Well, if you know how to hack the root acount, please post
> it. You cannot have real security through obscurity.
Please address any security concerns to smesecurity@mitel.com, and only there.
Posting security issues in public forums before contacting the vendor for comment and allowing them a reasonable time to reply is irresponsible and harmful.
We also do not believe in "security through obscurity". We do, however believe that the vendor should have the opportunity to address security issues before potentially putting large numbers of systems at risk.
That said, there is no evidence that there is anything wrong in this instance.
Gordon