> VULNERABILITY DISCLOSURE POLICY

TARGET: LUCA.ROSENLOECHER.ORG

01_INTRODUCTION

At luca.rosenloecher.org, we take the security of our systems and data very seriously. We appreciate the efforts of security experts who help us identify and report vulnerabilities responsibly. This policy describes how you can report security vulnerabilities to us and what you can expect from us.

02_OUR_COMMITMENT

If you adhere to the guidelines in this document:
* We will not take legal action against you.
* We will not attempt to sue you for damages caused by your research, as long as you have followed this policy.
* We will acknowledge your efforts if you wish.
* We will fix the vulnerability in a timely manner and keep you informed of our progress.

05_DOS

* Report ASAP after discovery. * Detailed reproduction steps. * Include PoC / screenshots. * Use PGP VIEW_PGP_KEY * Minimise system impact.

06_DONTS

* No data modification/theft. * No availability compromise. * No backdoors/persistence. * No publication before fix.

07_CHANNELS

Please send your report to: or use the form: https://luca.rosenloecher.org/report/. Include impact, steps, and affected URLs.
SEND_EMAIL VIEW_PGP_KEY

08_PROCESS

* CONFIRMATION: 5 working days.
* ANALYSIS: full validation.
* UPDATES: regular status.
* FIX: rapid resolution.
* COORDINATION: disclosure after fix.

09_RECOGNITION

If you wish and have complied with this policy, I will recognise you in our https://luca.rosenloecher.org/halloffame.html. This page is still under construction, as there are currently no reports.
PGP_PUBLIC_KEY // LUCA.ROSENLOECHER@PROTONMAIL.COM [X]
-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEaU7rUhYJKwYBBAHaRw8BAQdA9LdnHP2Zx/86oOJ2Fq/xPdnb1kLZH0Aa
LYmrll4rGoPNQ2x1Y2Eucm9zZW5sb2VjaGVyQHByb3Rvbm1haWwuY29tIDxs
dWNhLnJvc2VubG9lY2hlckBwcm90b25tYWlsLmNvbT7CwBAEExYKAIIFgmlO
61IDCwkHCRAl6nUtrWB+SEUUAAAAAAAcACBzYWx0QG5vdGF0aW9ucy5vcGVu
cGdwanMub3Jnkifh9t7Hm8altP4QbaMKRIVnZDPXiNLYTqS3PlPvmeoDFQoI
AxYAAgIZAQKbAwIeARYhBGoK9Suyr9B1escjFCXqdS2tYH5IAACDewEA8IWi
gcz7zS087OVgQ6lXkGv/Vbb7y2ExU85lYv5bfcwA/2M4bX/7zEa9GhXcyxUU
SxBPLJCVHmj5b6ZfTOxS89wDzjgEaU7rUhIKKwYBBAGXVQEFAQEHQNCCOLJ/
maHUD5LWo8f9x7N+6padrxlmLaCUzC3ma8FDAwEKCcK+BBgWCgBwBYJpTutS
CRAl6nUtrWB+SEUUAAAAAAAcACBzYWx0QG5vdGF0aW9ucy5vcGVucGdwanMu
b3JnG/TMruOubtonKPSYneHyaPXSGoLr3oAJ28jY1sF8rzsCmwwWIQRqCvUr
sq/QdXrHIxQl6nUtrWB+SAAAFAoBAKloBOByIq9fxBQs6j3k7kFFPzxR1ZNu
jTZ+lzfpmQzbAQCm7gUerwULO7lqN3FjN0sL2ALiA9Y8Ungy6TgTPzyFAQ==
=HcU9
-----END PGP PUBLIC KEY BLOCK-----