Is there an e-mail address I can respond to apart from security@ if I find more flaws? (Or anyone else reading this)

This is frustrating... try to e-mail and find that it bounces:

This is an automatically generated Delivery Status Notification

Delivery to the following recipient failed permanently:

  ----- Original message -----

Received: by with SMTP id j20mr7307212pym;
       Mon, 24 Jul 2006 03:21:27 -0700 (PDT)
Received: by with HTTP; Mon, 24 Jul 2006 03:21:27 -0700 (PDT)


If it was a serious hole, I'd probably either sit on it or e-mail someone directly, but here goes:

Message removed.