If you have found a vulnerability, we would rather hear about it from you than from an attacker. This page describes how to reach us, what we consider in scope, and what you can expect from us in return.
This page is the policy referenced by our security.txt.
Send your report by email to ops[BITTE-LÖSCHEN-SPAMSCHUTZ]@[BITTE-LÖSCHEN-SPAMSCHUTZ]hackingcult.de.
If the report contains sensitive details, please encrypt it with our S/MIME certificate found here: smime.crt
Encrypted mail is welcome, but plain mail is fine too. Do not let missing crypto stop you from reporting something urgent.
We read and reply in English and German.
A good report lets us reproduce the issue without a lot of back and forth:
The hackingcult.de domain and every subdomain under it are in scope. If it answers on a *.hackingcult.de name, we
want to hear about it.
Out of scope:
hackingcult.de. Including our published source code, repositories, and packages hosted
elsewhereWhile testing, please:
We will tell you how we classified the issue and why. If we disagree with your assessment, we will explain our reasoning rather than simply closing the report.
We do not set a fixed embargo period. We would rather agree on a disclosure date with you, per report, based on how bad the bug is and how long the fix realistically takes. Serious issues get fixed quickly and can be published quickly. Something obscure that needs a rewrite may take longer. Tell us early what your own timeline looks like. If you plan to publish on a particular date, or present at a conference, let us know in your first mail and we will work toward it.
If you follow this policy in good faith, we will treat your work as authorized security research. We will not pursue legal action against you, and we will not report you to law enforcement, for activity that stays within the rules above.
If a third party takes action against you over research that complied with this policy, we will make it known that your activity was authorized.
This is a statement of our own intent. It cannot waive the rights of third parties, and it does not override applicable law. Please act accordingly.
Safe harbour applies only to activity that follows this policy. Automated scanning, AI-driven testing, and anything that puts the availability of our systems at risk falls outside it. We treat that as unauthorized access to our infrastructure and reserve the right to pursue it accordingly, including by referring it to law enforcement.
There is no bug bounty here. We do not pay for reports, and we are not going to pretend otherwise.
What you get instead: a human reply from someone who understands what you sent, a real fix rather than a ticket that rots, an honest explanation if we decide not to fix something, and public credit on this page in whatever form you prefer.
Thanks to the people below for reporting security issues to us responsibly. Just tell us in your report if you would like to be listed or would rather stay anonymous.
No reports published yet
Gerolfinger Str. 106
85049 Ingolstadt
+49 (841) 9937 3456
ops[LOESCH-MICH-SPAMSCHUTZ]@[LOESCH-MICH-AUCH]hackingcult.de