Scott -- I agree with you that we don't want to help hackers trolling this (or other) sites. That said, I don't believe anything I have posted has shown any specifics of where the vulnerability (assuming it exists) might be.
Also, if DNN felt that something was too explicit, I would have no problem with DNN taking it down (you do moderate this site :)).
I do feel, though, that when the community can openly discuss what is going on it has great benefit to both the software corp (DNN) and the users. I like the forum on your site because it does enable you to allow open discussion with great feedback from all the experts.
In all honesty, this vulnerability scares me. Not only does it appear that someone is able to write to the module setting (perhaps via SQL insertion), but that from what I could collect via google searches, no one has posted a "how to fix it" article.
I really don't want to be a pest, I am just trying to point out what I, and my client, see as a priority to resolve quickly.
Thanks
Tim