Skip to content

Security: azmolhaque/security-writeups

Security

SECURITY.md

Security Policy

This repository publishes finished security research — findings that were reported to the affected party, remediated, and only then written up. It contains no live vulnerabilities and no working exploits against third-party systems.

Reporting something to me

Preferred: cindrasec.com/.well-known/security.txt Direct: contact@cindrasec.com · azmolhaque95@gmail.com

I read everything and reply, usually within a day. If you need encryption before sending details, say so and we will arrange it first.

If you have found something in my own systems

Anything I run — cindrasec.com, the SecretNode infrastructure, this account's repositories — is fair to report and I will thank you for it. Please give me a reasonable window to fix it before publishing, and I will keep you informed rather than going quiet.

If you think a writeup here is wrong

Open an issue, or email me. This applies to the technical mechanism, the severity calibration, or the translations. Calibration in particular is a judgement call, and I would rather be corrected in public than be confidently wrong in nine languages.

What I will not do

  • Publish a finding before the affected party has had the chance to fix it. Every writeup here went out only after remediation was confirmed.
  • Republish someone else's finding as though it were mine.
  • Write up a finding from a program whose disclosure terms forbid it. Some programs prohibit discussing findings outside the program entirely, including resolved ones. Those stay unwritten, however good the story would have been.

On the research itself

Testing behind these writeups was authorized — via a public bug-bounty or vulnerability disclosure program, an explicit written engagement, or against infrastructure I own. Where a target is named, either the program's terms permitted disclosure or permission was obtained.

Findings are rated as they actually are. The Google VRP writeup in this repository is credit-only rather than paid precisely because it was rated accurately instead of optimistically — that is the standard, not an apology for it.


Md. Azmol Haque Rony · @azmolhaque · cindrasec.com

There aren't any published security advisories