carlos@cesaints: ~/security/rules.md — zsh

Command: cat security/rules.md

security/rules.md · 1.2 KB · updated

Rules of engagement and publication

What I test

  • Only platform labs, my own systems or programs with current written authorization.
  • Nothing on third-party systems without explicit authorization, not even “just to look”. Since Law 14.155/2021, article 154-A of the Brazilian Penal Code no longer requires bypassing a security mechanism for an intrusion to be a crime.
  • Impact proven with my own accounts and minimal access; no third-party data collected.

What I publish

  • Writeups of retired content only, with the retirement date and the official link at the top.
  • Never certification exam content, nor a description of what an exam contained.
  • Paid labs only as a journey write-up, without solutions, when the platform’s rules ask for that.
  • Real vulnerabilities only after coordinated disclosure: a published fix or an agreed deadline, with the program’s permission and a timeline.
  • Screenshots and logs with personal data always masked.

Found a flaw in this site?

Write to the contact in /.well-known/security.txt. Don’t run tests that affect availability, don’t access other people’s data and give me a reasonable time to fix it. I’ll reply, fix it and credit you if you want.