Security

Vulnerability disclosure

Last updated 2026-10-08

We take the security of our websites and of the CTF platform seriously and welcome reports from researchers. This page is also published as security.txt.

Scope

  • In scope: cyrange.eu and the CTF platform at ctf.cyrange.eu (the platform, its configuration and our reverse proxy).
  • Out of scope: the challenges themselves (they are intentionally vulnerable, and attacking them is the game, within the terms), denial-of-service, social engineering or physical attacks, and third-party services.

How to report

Email info@cyrange.eu [TODO(Dan): dedicated security@ mailbox, if you want one] with a description, the affected address, steps to reproduce and your assessment of impact. Please do not include real personal data in the report.

Encrypted reports: [TODO(Dan): publish a PGP key or other secure channel and reference it here and in security.txt (Encryption field)]

What to expect

  • We aim to acknowledge your report within [TODO(Dan): acknowledgement time, e.g. 5 working days].
  • We keep you informed and tell you when the issue is fixed.
  • We ask for a reasonable period to fix before public disclosure [TODO(Dan): confirm, e.g. 90 days].
  • Rewards: [TODO(Dan): state whether any reward is offered; none is promised here].

Rules for research

  • Test only the in-scope systems and only with your own account and data.
  • Stop at proof of concept: do not copy, change or delete other people's data, and do not degrade the service.
  • Do not use social engineering and do not disclose the issue before we have had the chance to fix it.

Safe harbour

[TODO(Dan): safe-harbour statement for good-faith research; wording from counsel]