-
Notifications
You must be signed in to change notification settings - Fork 197
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Tod Beardsley
authored
Sep 2, 2020
1 parent
c2beb75
commit 5d375c2
Showing
1 changed file
with
35 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,35 @@ | ||
# Reporting security issues | ||
|
||
Thanks for your interest in making Recog more secure! If you feel | ||
that you have found a security issue involving Metasploit, Meterpreter, | ||
Recog, or any other Rapid7 open source project, you are welcome to let | ||
us know in the way that's most comfortable for you. | ||
|
||
## Via ZenDesk | ||
|
||
You can click on the big blue button at [Rapid7's Vulnerability | ||
Disclosure][r7-vulns] page, which will get you to our general | ||
vulnerability reporting system. While this does require a (free) ZenDesk | ||
account to use, you'll get regular updates on your issue as our software | ||
support teams work through it. As it happens [that page][r7-vulns] also | ||
will tell you what to expect when it comes to reporting vulns, how fast | ||
we'll fix and respond, and all the rest, so it's a pretty good read | ||
regardless. | ||
|
||
## Via email | ||
|
||
If you're more of a traditionalist, you can email your finding to | ||
[email protected]. If you like, you can use our [PGP key][pgp] to | ||
encrypt your messages, but we certainly don't mind cleartext reports | ||
over email. | ||
|
||
## NOT via GitHub Issues | ||
|
||
Please don't! Disclosing security vulnerabilities to public bug trackers | ||
is kind of mean, even when it's well-intentioned, since you end up | ||
dropping 0-day on pretty much everyone right out of the gate. We'd prefer | ||
you didn't! | ||
|
||
[r7-vulns]:https://www.rapid7.com/security/disclosure/ | ||
[pgp]:https://keybase.io/rapid7/pgp_keys.asc?fingerprint=9a90aea0576cbcafa39c502ba5e16807959d3eda | ||
|