This repository publishes finished security research — findings that were reported to the affected party, remediated, and only then written up. It contains no live vulnerabilities and no working exploits against third-party systems.
Preferred: cindrasec.com/.well-known/security.txt
Direct: contact@cindrasec.com · azmolhaque95@gmail.com
I read everything and reply, usually within a day. If you need encryption before sending details, say so and we will arrange it first.
Anything I run — cindrasec.com, the SecretNode infrastructure, this account's
repositories — is fair to report and I will thank you for it. Please give me a
reasonable window to fix it before publishing, and I will keep you informed rather
than going quiet.
Open an issue, or email me. This applies to the technical mechanism, the severity calibration, or the translations. Calibration in particular is a judgement call, and I would rather be corrected in public than be confidently wrong in nine languages.
- Publish a finding before the affected party has had the chance to fix it. Every writeup here went out only after remediation was confirmed.
- Republish someone else's finding as though it were mine.
- Write up a finding from a program whose disclosure terms forbid it. Some programs prohibit discussing findings outside the program entirely, including resolved ones. Those stay unwritten, however good the story would have been.
Testing behind these writeups was authorized — via a public bug-bounty or vulnerability disclosure program, an explicit written engagement, or against infrastructure I own. Where a target is named, either the program's terms permitted disclosure or permission was obtained.
Findings are rated as they actually are. The Google VRP writeup in this repository is credit-only rather than paid precisely because it was rated accurately instead of optimistically — that is the standard, not an apology for it.
Md. Azmol Haque Rony · @azmolhaque · cindrasec.com