Security
Report a security issue.
If you have found a vulnerability in dorzun.com or one of its subdomains, tell us. This page explains how to report it and what to expect from us.
How to report
This is the address published in our security.txt file. Please write in English and send one report per issue.
What to include
- The affected URL, host or component.
- What the issue is, and the impact you believe it has.
- Clear steps to reproduce it, with any proof-of-concept code, requests or screenshots.
- When you tested, and from which IP address, so we can find your activity in our logs.
- How to reach you with follow-up questions.
Classified information
Never send classified information or export-controlled technical data, in a report or in any other message to DORZUN, even if you believe it is relevant.
If a report seems to need it, describe the issue without that material and tell us that you left something out. Classified information may only be shared through channels the U.S. government has authorized for it.
In scope
dorzun.com and its subdomains, including the website, its contact and application forms, and the domain’s DNS and email configuration.
Systems run by our hosting and email providers belong to them. Please report issues in their platforms to them directly.
Out of scope
- Denial-of-service attacks, and any testing that degrades the site or its availability for others.
- Social engineering, including phishing, aimed at DORZUN staff, contractors or providers.
- Physical attacks against people, property or equipment.
- Spam, including large volumes of messages sent through the contact form.
- Output from automated scanners without a proof of impact.
- Reports of missing best-practice settings, such as security headers or email authentication records, without a demonstrated attack.
Safe harbor
If you make a good-faith effort to follow this page, we will consider your research authorized and not a breach of our Terms of use. We will not pursue or recommend legal action against you for it, and if someone else does, we will make it known that your research was authorized. We will work with you to understand and fix the issue.
Good faith means that you:
- avoid harm to people, privacy violations, destruction of data and interruption of service;
- access only the data you need to show the issue, stop once you have shown it, and tell us;
- stop at once and tell us if you reach personal information, technical data or anything marked as controlled, and do not copy it;
- do not keep, share or use any data you come across;
- give us reasonable time to fix the issue before you discuss it with anyone else.
This statement covers DORZUN only. We cannot authorize testing of systems that others run, and we cannot speak for law enforcement or other authorities. Where the law requires us to report a security incident, we will.
What happens next
We aim to acknowledge your report within three business days, then to tell you whether we could reproduce the issue, keep you informed while we work on it, and let you know when it is fixed.
Rewards
We do not offer bug bounty payments for now. If that changes, this page will say so.