Responsible disclosure
If you found a security issue in this website or in Hackerbane's own systems, send it here. There is no bug bounty.
How to send it
Email security@hackerbane.com. Write in English. Include the URL or file, what you think is wrong, and the steps to reproduce it.
Do not use the request form for this. That inbox is for audit work.
In scope
- hackerbane.com, including the request form and this page.
- Mail handling for the Hackerbane inboxes named on this site.
Out of scope
- A client's product. Tell them, or tell us only if they asked us to handle it.
- Bugs in other people's open-source projects. Those go to the project. Our published reports are research notes, not an inbox for those repos.
- Social engineering, physical access, or denial of service.
- Automated scans that knock the site over.
What we ask
Give us a chance to fix it before you publish. Do not pull request data that belongs to someone else. Do not keep a copy of anything you did not need to prove the issue.
What we do
We read the mail. We reply when we have something to say. We do not pay for reports. We do not run a bounty platform.
The same contact is in /.well-known/security.txt.