Skip to content

Security: akinerkisa/NoMoreForbidden

Security

SECURITY.md

Security Policy

NoMoreForbidden is a security testing tool. Use it only against systems you own or are explicitly authorized to test. The default safety controls are part of the product contract, not a replacement for authorization.

Reporting a security issue in this project

Do not open a public issue for an undisclosed vulnerability in NoMoreForbidden or in the bundled lab. Contact the maintainers privately through the GitHub repository owner profile or use GitHub private vulnerability reporting if it is enabled. Include a minimal reproduction, affected version, impact, and a suggested mitigation. Do not include credentials, live target data, or secrets.

Scope

Reports about the intentionally vulnerable renikApp scenarios should explain which lab route and expected educational behavior are involved. Reports about third-party targets belong with the target owner or program, not in this repository.

There aren't any published security advisories