Reporting a security issue
Pushup RPG · the website, the apps and the service behind them
If you have found a way to see or change something you should not be able to, in the apps, on this website or in the service the apps talk to, we want to hear about it.
How to report
Email hello@pushup.quest with Security in the subject, and please do not open a public issue first. Put the details in the first email:
- what you found, and where: a URL, a screen in the app, or a request;
- the steps that reproduce it;
- what someone could do with it.
We reply to reports that include enough to reproduce the problem. A message that only says you have found something, without saying what, gives us nothing to act on.
While you are testing
- Use only accounts you own. If you reach another player’s data, go no further than you need to show that you can, do not keep it, and tell us.
- No denial of service, no load testing, and no automated scanning heavy enough to slow the service down for players.
- No social engineering of players or of us.
No bug bounty
We do not run a bug bounty and we do not pay for reports. We will not sign an agreement or discuss terms before receiving a report: send the details, and we will read them.
What we do not treat as a vulnerability on its own
- Missing or “weak” security headers, without a working attack they would have stopped.
- SPF, DKIM or DMARC settings on our email domain.
- Clickjacking on a page that has no action to hijack.
- Version numbers or software banners.
- Self-XSS, or anything that needs the victim to paste code into their own browser.
- Output from an automated scanner with no demonstrated impact.
If you think one of these does matter in our case, show us how, and we will treat it like any other report.
The machine-readable version of this page is at /.well-known/security.txt. For anything that is not a security issue, the contact page has the right address.