Responsible Disclosure
We want to know about security issues in the UzHackHub platform itself, reported safely. If you find something, this page explains what to report, how to report it and what you can expect from us.
What to report
- Bugs that could harm users, such as XSS or broken authentication.
- Data exposure, including unintended access to other members' data.
- Rate-limit bypasses on our platform.
- Content abuses, such as posts that break our community rules.
How to report
- Message the moderators on Telegram with a concise description of the issue.
- Include steps to reproduce the issue and its impact.
- Do not exploit the issue further than needed to confirm it.
- Do not share the issue publicly before we have fixed it.
What we promise
- We respond to every report.
- We keep reporters informed as we investigate and fix issues.
- We credit researchers in our changelog when we fix their findings.
Out of scope
- Testing other websites or systems is not part of this policy.
- This policy covers the UzHackHub platform only.
If you are unsure whether testing is allowed - it is not, until you ask.
Asking first is always welcome and never penalized.
Report an issue