If you have found security vulnerability, report it privately. Please do not publish it until the correction has been omitted and the disclosure date has been agreed.
How to report
- E-mail: incident [at]cyb3r.help (reply 24/7)
- Machine-readable contact: /.well-known/security.txt (RFC 9116)
What to report
- Description and impact
- Steps to Repeat
- Affected page or component
- Would you like us to make a statement
What we promise
- Receipt confirmation - within 3 working days
- Initial assessment (severity, scope) - within 7 working days
- Correction - 30 days for critical, 90 days for others
- Public notice after correction, date matching with you
The severity of CVSS v3.1. The public recognition page has not yet been created - if you want us to mention you, say it in the report, and let us agree on the form.
What is not vulnerability
- Missing good practice without specific use
- Denial of service without breach of access rights
- Social engineering against people and physical access
- Sensitivity of third party services - reports directly to their provider
- Content of adverts - it is a modelation, not a security issue (the complaint button is in every advertisement)
Testing limits
We do not allow tests that damage data to interfere with other users or access foreign accounts. If a check requires an account, create your own.