Responsible Disclosure
Found a security problem here? Tell us — we will not punish you for it.
Reporting a vulnerability
If you have found a security problem on webrefer.net, please tell us at [email protected]. Include:
- what the issue is and where you found it;
- the steps needed to reproduce it;
- the impact you think it has.
We will acknowledge your report, keep you updated while we investigate, and credit you if you would like to be credited. Please give us a reasonable opportunity to fix the issue before you disclose it publicly.
How this site is built
webrefer.net is served over HTTPS with HSTS, a Content-Security-Policy that permits scripts only from this origin, and cross-origin isolation headers. There is no login, no web form and no visitor database — so there is no enquiry store to breach. Analytics load only after you accept them, and web fonts are served from this domain rather than a third party.
Please do not
- Access, alter or delete data that is not yours.
- Run denial-of-service, load or spam tests against the site.
- Test the infrastructure of our clients, or of any third-party website that appears in our datasets — those systems are not ours and we cannot authorise you to touch them.
- Use social engineering against our people, or attempt physical access.
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised, and we will not pursue or support legal action against you over it. If you are not sure whether something is in scope, ask first at [email protected].
A machine-readable version of this contact is at /.well-known/security.txt.
Related: Data & Removal Requests · Privacy Policy