Security and Disclosure

Machine-readable contact details are published at /.well-known/security.txt.

Reporting a vulnerability in this site

Reports are welcome. Email ahmedramadan.ar16148@gmail.com with enough detail to reproduce the issue: affected URL, steps, and the impact you believe it has.

You can expect an acknowledgement within 72 hours, an assessment within seven days, and credit in the fix notes unless you would rather stay anonymous.

Scope

This site is a statically generated publication. It holds no user accounts, no database, and no personal data. In scope: anything reachable under this domain.

Out of scope: findings against third-party infrastructure that merely hosts or fronts this site, missing headers with no demonstrated impact, automated scanner output without a working proof of concept, and reports whose only finding is that a disclosed software version exists.

Safe harbour

Good-faith research consistent with this policy will not be met with legal action. Please avoid degrading the service, pivoting to infrastructure that is not mine, and accessing or retaining data that is not your own. If you reach something you were not expecting to reach, stop and describe it rather than exploring further.

Disclosure policy for my own research

Vulnerabilities I find in third-party software are handled under coordinated disclosure. The vendor is contacted first and given 90 days before publication. That window extends where a vendor is engaged and working toward a fix, and shortens where a vulnerability is already being exploited or is public by other means.

Advisories published here appear only after a fix is available, the disclosure window has closed, or the vendor has confirmed they do not intend to act. Where a CVE has been assigned, it is cited.

On the research published here

Technical content on this site documents offensive security techniques for practitioners: defenders who need to understand what they are defending against, and testers working under authorisation.

None of it derives from client engagements. Techniques are demonstrated against systems I own or am explicitly authorised to test, or against deliberately vulnerable software built for the purpose. Running any of it against a system you do not have written permission to test is likely a criminal offence in your jurisdiction, and it is your responsibility, not mine.