Disclosure policy

How to report security vulnerabilities on the cyb3r.help platform and what to expect after the report.

If you have found security vulnerability, report it privately. Please do not publish it until the correction has been omitted and the disclosure date has been agreed.

How to report

  • E-mail: incident [at]cyb3r.help (reply 24/7)
  • Machine-readable contact: /.well-known/security.txt (RFC 9116)

What to report

  • Description and impact
  • Steps to Repeat
  • Affected page or component
  • Would you like us to make a statement

What we promise

  • Receipt confirmation - within 3 working days
  • Initial assessment (severity, scope) - within 7 working days
  • Correction - 30 days for critical, 90 days for others
  • Public notice after correction, date matching with you

The severity of CVSS v3.1. The public recognition page has not yet been created - if you want us to mention you, say it in the report, and let us agree on the form.

What is not vulnerability

  • Missing good practice without specific use
  • Denial of service without breach of access rights
  • Social engineering against people and physical access
  • Sensitivity of third party services - reports directly to their provider
  • Content of adverts - it is a modelation, not a security issue (the complaint button is in every advertisement)

Testing limits

We do not allow tests that damage data to interfere with other users or access foreign accounts. If a check requires an account, create your own.