Skip to content

Security: atmflow55/tls-scanner-community

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you find a security issue in this scanner, please email contact@toughlovesec.win with:

  • A description of the issue
  • Steps to reproduce (or a proof-of-concept)
  • Your assessment of severity

Please do not open a public issue, post to social media, or demonstrate the vulnerability against systems you do not own.

What to expect

  • Acknowledgement within 72 hours
  • Status update within 7 days
  • Coordinated disclosure timeline: 90 days from initial report, or earlier if a patch ships and is adopted

We do not currently offer a paid bug bounty, but we credit reporters in release notes unless you request anonymity.

In-scope

  • server.js — the HTTP wrapper (auth bypass, RCE, path traversal, SSRF)
  • scan.sh and scanners/*.sh — the scan orchestrator (command injection via target URL, payload handling)
  • Dockerfile / fly.toml — deployment hardening concerns

Out of scope

  • Findings produced by the scanner on third-party sites
  • Denial-of-service against the scanner itself via malformed input (file issues for these)
  • Social engineering, physical attacks

Responsible use

This tool sends active payloads. Only scan systems you own or have written authorization to test. Unauthorized scanning is illegal in most jurisdictions. We are not responsible for misuse.

There aren't any published security advisories