security · responsible disclosure
Report a security issue.
If you think you have found a vulnerability in anything I run, please tell me so I can fix it. Good-faith reports are welcome.
How to report
Email security@happypaul55.com with the details. To help me reproduce and fix the issue quickly, please include:
- The affected site or service, and the URL where it occurs.
- A description of the issue and what an attacker could do with it.
- The steps to reproduce it, and any proof of concept.
- Any screenshots, logs or requests that show the problem.
What to expect
- I aim to acknowledge your report within three working days.
- I will investigate it, keep you updated, and tell you whether I consider it a vulnerability.
- I will let you know when a fix has shipped and, if you would like, credit you for the report.
Please do not
- Access, change or delete data that does not belong to you.
- Disrupt or degrade these services, or anyone else's.
- Run automated scans that generate significant load.
- Disclose the issue publicly before I have had a reasonable chance to fix it.
Scope
This policy covers happypaul55.com and its subdomains, together with pokerhudxl.com. It does not cover third-party products or services that I use but do not control.