Pooh:

Who are you to dare badger the other side?
It's my JOB to badger, harass, be deceptive with, deny information to and generally make thier lives as difficult as possible. I don't give a rats ass if it makes their little lives problematic... I could care less if their little bottom lip curls and the pitch a bitch fit..... In fact it's my aim in life These liitle monkeys are little short of cyber terrorists and we have seen what happens when you don't make terrorists lives difficult. It's no different in our virtual world.

So tell me this, would you rather have the exploits found by others kept secret
Pooh, gimme a break..... If Spy is malicious he's not someone who is teaching me anything. He doesn't know where to find the goddamn log files.... Yeah, he's l337 . More likely, (should he be malicious), that he is one of the little monkeys I refer to above that wants to be l337 but doesn't have a clue. (NOTE: I am not making judgement on Spy himself at this point).

You can't honestly say that without exploitation testing by black/grey hats, that the world would be a better/secure place?
I don't say that. I agree. But you are utterly out of context. When a know-nothing script kiddie comes here asking how to cover his tracks after his successful "sploit" we aren't talking about a blackhat hacker/cracker. We are talking about a malicious little child who is too lazy or too stupid to be able to research the subject for themselves so they come here hoping for the "quick fix". It pleasures me no end to send them away without the information because, in my mind I'm hoping that the admin who let them in, (and let's be honest here - if the kiddie can get in then the admin was not paying proper attention), is smart enough to realize he's been hacked and catches the perpetrator because the log files are still intact......

try to help him.
The best way I can help him is to not provide him with the information. If I give it to him this time he may get away with it and take on a bigger target with an admin that isn't as lax as the first. Then he goes to jail. How did I help him by making him think he is l337? Go back through my posting history..... You will find occasions where I, and others, have discussed the ethics of what they want to do and they have stated that we have changed their minds about their plans.... Can one truly believe them? No..... But making them at least think about it is much closer to helping them!!!!!!

"If you can not help someone, do not choose to hurt them instead"
Pooh.... If you attack, or intend to attack, myself, my family, my friends or my community you had better be prepared to deal with me if I find out about it. Anyone who partakes of mailicious activity, especially the kiddies who are really only preying on the most helpless, will be treated with utter contempt, will receive no assistance from me and if I can assist in harming them, (getting them in trouble with law enforcement), I will. It's really that simple.

If you are so keen on the free passage of information perhaps you would like to post your network's architecture, IP address range, implemented security systems etc. here for all of us to see. What, you won't! Why Pooh? Because it is a preposterous suggestion isn't it? But why is it any more preposterous than telling a know-nothing skiddie who is just a hair away from being caught because he didn't think things through properly how to get himself out of trouble????????

Freedom of and exchange of information is fine in most businesses. But not in security. The truly talented malicious crackers out there don't publish their findings.... They call them "zero-days" and use them against their victims. You seem to see them as some kind of knights in slightly tarnished armour. They aren't, and the sooner you understand that the better. They are the enemy and need to be treated as such lest they chose you next. They won't come nicely from the front, Pooh..... They will sneak up behind you and "stab you in the back" smiling all the while, because that's who they are.