Security
How to report something you found in the platform itself.
Reporting
Email security@hafezsecure.ir with what you found and how to reproduce it. If you can, include the request, the response, and roughly when it happened so we can find it in the logs.
Please do not open a public issue for a security problem, and please do not test against other people's accounts or environments to prove it — a description is enough.
Scope
In scope: this platform — the web application, its API, the environment provisioning, and how challenge containers are isolated from each other and from us.
Out of scope: the challenges themselves. Those are meant to be broken; that is the point.
What to expect
We will confirm we received it, tell you whether we consider it a vulnerability, and let you know when it is fixed. We do not currently run a paid bounty.
Testing in good faith against your own account, reported to us and not exploited further, is welcome. We will not pursue anyone who does that.
Other pages: Privacy · Terms · Acceptable use