Except for the communication and the lack of responsible disclosure. Publishing the exploit without contacting first the security teams of tools as big as postfix... Is quite bad.
> Unfortunately, criticial information provided by the researcher was not passed on to Postfix maintainers before publication of the attack, otherwise we would certainly have convinced SEC Consult to change their time schedule until after people had a chance to update their Postfix systems.