OK, if I tested a system for vulnerabilites, without delving deep into the breaches of secuirty, and never actually accessed the system illegally, but I actually know that If I try without too much effort could get in; and I intend on reporting the problems to the right person, without disclosing any of the vulnerabilites in the system to anyone, am I doing the right thing, or should I just walk away from the situation?
And if I should proceed to inform the admin, how should I put together my findings? I simple email wouldn't be effective, I think....




