When it comes to vulnerability reporting and/or disclosure, there are two schools of thought; "responsible disclosure" and "full disclosure". Unfortunately, what "full disclosure" and "responsible disclosure" actually mean can vary a whole lot. For example, some define "full disclosure" as immediately publishing/disclosing the vulnerability and/or with working exploit code, but more level-headed folks define "full di…
Thank you so much for this. (xpto123 as well). I tried calling but just got bounced around and I'm not sure anyone actually understood/cared. I've got a nice early season cold going so not really interested in sitting on the phone for hours so I've given up on that. I'm going to email blast as many of the emails I can get and if I don't hear anything back from them by Monday I'll pass it onto CERT.
The law is not on your side in most countries, there are honest security researchers in jail for doing things like this, so beware of your personal safety at all times.
If you already identified yourself and followed their security submission page and they did not follow up, then its best to leave it at that. Above all don't get in personal trouble because of this, it's not worth it.