diff options
author | pandaninjas <101084582+pandaninjas@users.noreply.github.com> | 2022-12-25 16:31:17 +0000 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-12-25 16:31:17 +0000 |
commit | d44a6c38c27e6df63a0477145f93dcb1097d01e9 (patch) | |
tree | 4ff1794bc2c52fea5ca85ea360692e0ada8049f0 | |
parent | dfcd4f594056572cb4b666d7ee9934e9810c0701 (diff) | |
download | NoSession-d44a6c38c27e6df63a0477145f93dcb1097d01e9.tar.gz NoSession-d44a6c38c27e6df63a0477145f93dcb1097d01e9.tar.bz2 NoSession-d44a6c38c27e6df63a0477145f93dcb1097d01e9.zip |
Update SECURITY.md
-rw-r--r-- | SECURITY.md | 16 |
1 files changed, 6 insertions, 10 deletions
diff --git a/SECURITY.md b/SECURITY.md index da25fbf..d9d5e6d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -10,17 +10,13 @@ Currently all versions are supported. ## Reporting a Vulnerability -Use this section to tell people how to report a vulnerability. - -Tell them where to go, how often they can expect to get an update on a -reported vulnerability, what to expect if the vulnerability is accepted or -declined, etc. - -A vulnerability is currently defined as being able to get the session ID with only a mod that gets loaded after NoSession loads its tweaker. -A non-comprehensive list of out of scope vulnerabilities: -- Stealing information from launcher files -- Using the OS level args methods +A vulnerability is currently defined as being able to get the session ID with only a mod that gets loaded after NoSession loads its tweaker.<br> +Vulnerabilities that are out of scope are defined as those that NoSession itself cannot prevent. However, if you can produce a patch for an out of scope vulnerability, a bug bounty will be awarded as well. The bug bounty is a $5 USD Amazon Gift Card. I might run out, so it's awarded on a first come, first serve basis. + +Report the bug bounty by emailing admin@malwarefight.gq or by sending a DM to PandaNinjas#3017 on Discord.<br> +If you would like, you can encrypt the message with my [public GPG key](https://raw.githubusercontent.com/pandaninjas/pandaninjas/main/pandaninjas-publickey.key)<br> +Your bug bounty may be invalidated if you disclose it to the public before. |