Skip to content

Security: MoDarK-MK/MoD

docs/SECURITY.md

πŸ” Security Policy

Reporting Security Vulnerabilities

If you discover a security vulnerability in this project, please report it responsibly.

Do NOT:

  • ❌ Open a public GitHub issue
  • ❌ Share details in forums or discussions

DO:

  • βœ… Email: hfg1533@gmail.com
  • βœ… Include vulnerability details and proof-of-concept
  • βœ… Allow 7-14 days for initial response
  • βœ… Avoid accessing other users' data

Response Timeline

Stage Timeline
Acknowledgment 24 hours
Initial Assessment 3 days
Fix Development 7-14 days
Security Release ASAP after fix
Public Disclosure 30+ days after release

Scope

βœ… In Scope

  • Code vulnerabilities (RCE, SQL Injection, XSS, etc.)
  • Authentication/Authorization flaws
  • Cryptographic weaknesses
  • Information disclosure
  • Denial of Service

❌ Out of Scope

  • Social engineering
  • Physical security
  • Third-party vulnerabilities
  • Theoretical/low-impact issues
  • Missing security headers (unless critical)

Security Best Practices

Using This Tool

  • βœ… Always get written authorization before testing
  • βœ… Use on systems you own or have permission to test
  • βœ… Keep the tool updated to latest version
  • βœ… Review scan results before taking action
  • βœ… Validate findings independently

Contribution Security

  • βœ… Sign commits with GPG when possible
  • βœ… Follow the Code of Conduct
  • βœ… Don't commit secrets or credentials
  • βœ… Use secure coding practices

Supported Versions

Version Status Support Until
3.0.x Active Nov 2026
2.5.x Security Fixes Nov 2025
< 2.5 Unsupported Ended

Disclaimer

This tool is provided as-is for authorized security testing only. Users are responsible for:

  • Obtaining proper authorization
  • Complying with applicable laws
  • Protecting user data
  • Using the tool ethically

Misuse of this tool may violate laws. Use responsibly.


Last Updated: November 2025

There aren’t any published security advisories