Reports are considered in-scope if they involve the following:
- Red Sun Loadout
- Red Sun Forums
- In-Game Loadout Core plugins
- Red Sun Exclusive (RSX) sub-plugins
- Red Sun Gamemodes
Additionally, reports will be considered in-scope if they involve a public plugin known to run on our Game Servers which exposes a significant vulnerability e.g. RCE, Arbitary input etc.
Reports are NOT considered in scope for the following services:
- Red Sun FastDL
- Third Party Platforms (e.g. Discord)
Use this section to tell people how to report a vulnerability.
Please include details of:
- The type of issue found
- Steps on how to replicate the issue
- Evidence of the issue (pictures, video etc. We ask that any data exfiltrated is anonymised and deleted after verification, and not spread to unauthorized parties.).
- Proof of Concept tools/exploits used
- Suggested remediation (optional)
- Name to be credited under (optional)
Once a vulnerability has been found and patched, we will assess the scope and severity of the disclosed vulnerability. On confirmation of the information, we may choose to offer you a bug bounty.