Vulnerability disclosure
If you have found a security problem in something operated here, this page tells
you where to send it and what happens next. It applies to every domain listed in
the Impressum, including all *.mayer.rocks services and the satire sites.
How to report
Email the address published in the Impressum: https://impressum.mayer.rocks/
Every property also serves /.well-known/security.txt pointing to the same place.
Please include enough detail to reproduce the issue. A short proof of concept is
worth more than a scanner report.
What you can expect
An acknowledgement within 72 hours that a human has read your report.
An assessment within 14 days: whether it is confirmed, what the impact looks
like, and roughly when it will be fixed.
Credit in the fix, if you want it. Say so, and say how you want to be named.
No bounty. This is a personal infrastructure run by one person; there is no
budget, and pretending otherwise would waste your time.
Safe harbour
Good-faith research will not be met with legal action. Good faith means: you
stop at proof of concept, you do not access, modify or exfiltrate data that is
not yours, you do not degrade a service for others, and you give a reasonable
opportunity to fix the issue before disclosing it publicly.
If you are unsure whether something is in scope or would cross a line, ask
first. Asking is always in scope.
Out of scope
Reports produced solely by an automated scanner, with no demonstrated impact.
Missing hardening headers with no exploitable consequence.
Findings against third-party services merely linked from these sites.
Social engineering, physical access, and denial of service.
Advisories against dependency versions that are not reachable in the deployed
configuration — most of these sites are static exports with no server-side
runtime, so a great deal of tooling finds a great deal of nothing.