Responsible disclosure
Found a vulnerability in axnet? Tell us first.
Version 0.2Updated Adopted by axnet on
1. Reporting
1.1 E-mail security@axnet.nl, in Dutch or English. Also in security.txt.
1.2 Include:
- the issue and where it is: URL, IP address or component;
- the steps to reproduce it, with a proof of concept;
- the possible impact;
- how we can reach you.
1.3 You may report anonymously. We then cannot keep you informed.
2. What we promise
2.1 axnet responds within 5 working days with a first assessment.
2.2 axnet keeps you informed until the issue is fixed, and agrees on disclosure with you.
2.3 axnet treats your report as confidential and does not share your details without your consent, unless the law requires it.
2.4 If you follow these rules in good faith, axnet will not report you to the police or take legal action against you.
2.5 If you wish, axnet credits you as the finder once the issue is fixed.
3. What we ask
3.1 Report it as soon as possible, and only to axnet.
3.2 Do no more than needed to show the issue:
- use only your own accounts, machines and data;
- do not disrupt the service and do not access other customers; show a flaw in the isolation between two accounts of your own;
- do not view, copy, change or delete other people’s data; if you come across it, stop and report it;
- do not place backdoors or change systems;
- no brute force, DDoS, spam, social engineering or physical access.
3.3 Do not share the issue with anyone until it is fixed. Disclose it only in agreement with axnet.
4. In scope
- axnet.nl;
- console.axnet.nl and the API;
- the isolation between customers: from your own machine to the host, the network or other customers;
- the network and the axnet firewall.
5. Out of scope
- customers’ machines, containers and websites: report those to the customer, or through Report abuse;
- third-party services, such as Mollie and GitHub: report those to them;
- DDoS, spam, social engineering and physical attacks;
- findings without a demonstrable risk, such as missing headers, version numbers, self-XSS, clickjacking on pages without actions, SPF or DMARC settings and unverified scanner output.