// SECURITY

Found something? Tell us.

We are an information security group, so it would be embarrassing to make this hard. Report in good faith and you will get a real answer from a person.

[email protected]

Scope

www.zoosec.net and zoosec.net — the website and its signup endpoint. That is the whole estate. We do not run an app, an API, or member accounts, and we do not own the venue's network or any service linked from these pages.

Out of scope

Findings from a scanner with no demonstrated impact: missing headers on static pages, cookie flags, TLS cipher preferences, version banners, SPF or DMARC opinions, clickjacking on pages with no state to change, rate limits on a form that only writes an email address. Also out of scope: social engineering of members, physical access at the venue, denial of service, and anything requiring a compromised device to begin with.

What we would genuinely like to hear about

Anything that reads or alters the subscriber list, bypasses the Turnstile challenge on the signup endpoint, injects script into a page, takes over the domain or its DNS, or exposes a credential we have leaked somewhere. In short: something you could actually do, not something a header check told you about.

How to report

Email the address below with enough detail to reproduce it — a request, a payload, a screenshot. Say whether you want credit and under what name. If you would rather hand it over in person, we meet the third Tuesday of every month and you are welcome to bring it then.

What we promise

We will acknowledge inside five working days and tell you what we intend to do. We will not involve lawyers or law enforcement over a good-faith report, and we will not ask you to sign anything to receive an answer. There is no bounty — this is a volunteer meetup with no budget — but we will credit you here if you want it, and buy you a drink at the next one.

What we ask

Test only against the scope above, and only with accounts and data that are yours. Do not run automated scanners hard enough to affect other visitors. Do not access, modify, or retain anyone else's data — if you reach subscriber records, stop, tell us what you saw, and delete your copy. Give us a reasonable window to fix something before you publish it; ninety days is the norm and we will usually be much faster than that.

← Back to the sitesecurity.txt

Last updated: