Vulnerabilities reporting

Responsible disclosure

Have you discovered a security flaw in an system belonging to Netrunner? Please notify us before informing the outside world, so that we can first take action. Doing so is called ‘responsible disclosure’.

What to do:

– Send email to address security@netrunner.com.pl to the Netrunner Tech Team
– Give enough detail to enable us to reproduce the flaw so that it can be remedied as soon as possible. The computer’s IP address or Netrunner system’s URL and a description of the security flaw is usually sufficient. The more complicated the flaw, the more detail we will require.
– Leave your contact details so that we can contact you later. At least an email address or telephone number.
– Report the flaw as soon as possible after discovering it.
– Do not share any information about the flaw with others until it has been remedied.
– Deal responsibly with the information in your possession. Do nothing beyond what is necessary to demonstrate the security flaw.

What not to do:

– Send malware;
– Copy, change, or delete data in the Netrunner system concerned (as an alternative, you can create a directory listing of the system);.
– Change the system;
– Repeatedly visit the system or share access with others;
– Use ‘brute force’ to open the system;
– Try denial of service or social engineering.

What to expect:

– When you report the security flaw, check that you comply with the conditions described above. If you do so, we will not attach any legal consequences to your notification.
– We treat the notifications confidentially. We will not share your personal details with third parties without your permission unless required to do so by law or a court order.
– We will send you an acknowledgement of receipt within one working day.
– We will respond to your notification within five working days. Its response will contain an assessment of your notification and the date on which it expects to remedy the flaw.
– We will keep you – as the one who discovered the flaw – informed of the progress made in remedying it.
– We will remedy the flaw as soon as possible, certainly no later than 21 days after receiving the notification
– Currently, we are not in position to reward researcher for their findings, but at least we will thank you and acknowledge publicly the findings with research attribution.