🛡️ Politique de divulgation — MySelf Security
Bienvenue, et merci. Si tu es là, c'est que tu veux nous aider à rendre MySelf plus solide. On accueille ça à bras ouverts. Cette page fixe le cadre pour que tout le monde soit tranquille — toi comme nous.
✅ Périmètre autorisé (in-scope)
ctf.my-self.fr — notre laboratoire volontairement exposé. Tout y est permis via HTTP : auth, logique applicative, injections, crypto. C'est fait pour être cassé.
⛔ Hors périmètre (out-of-scope — strict)
- Toute la vraie prod :
my-self.fr et ses autres sous-domaines, cannabiocreuse.fr, l'infrastructure, le réseau local.
- Le déni de service (DoS, flood, stress) — ça ne teste rien, ça casse juste.
- L'exfiltration de masse — une preuve suffit, pas besoin de vider une base.
- La destruction de données ou de comptes, le pivot vers du hors-scope, l'ingénierie sociale, le physique.
🤝 Notre engagement (safe harbor)
Tant que tu restes dans le périmètre autorisé et de bonne foi, on considère ta recherche comme légitime et autorisée. On n'engagera aucune poursuite et on ne préviendra pas ton hébergeur. On s'engage à accuser réception, analyser, corriger, et créditer ta trouvaille (au Hall of Fame ou en privé, comme tu préfères).
📨 Comment nous signaler une faille
Utilise le formulaire ci-dessous : ton rapport est chiffré en PGP dans ton navigateur avant l'envoi — nous seuls pouvons le lire. Donne-nous de quoi reproduire : étapes, endpoint, impact.
🤖 Outils IA
Bienvenus comme assistants — mais valide toi-même ce que tu soumets. Un rapport reproductible vaut de l'or ; un copier-coller de LLM non vérifié nous fait perdre du temps à tous les deux.
Souci avec le formulaire ? Contact direct : security@my-self.fr
Respect à tous les curieux. 🌱
🛡️ Responsible Disclosure Policy — MySelf Security
Welcome, and thank you. If you're here, you want to help make MySelf more robust. We welcome that with open arms. This page sets the ground rules so everyone's covered — you and us.
✅ In scope
ctf.my-self.fr — our deliberately exposed lab. Anything goes over HTTP: auth, application logic, injections, crypto. It's built to be broken.
⛔ Out of scope (strict)
- All real production:
my-self.fr and its other subdomains, cannabiocreuse.fr, the infrastructure, the local network.
- Denial of service (DoS, flooding, stress) — it tests nothing, it just breaks things.
- Mass exfiltration — one proof is enough, no need to dump a database.
- Destroying data or accounts, pivoting to out-of-scope, social engineering, physical attacks.
🤝 Our commitment (safe harbor)
As long as you stay in scope and act in good faith, we consider your research legitimate and authorized. We will take no legal action and won't notify your host. We commit to acknowledge, analyze, fix, and credit your finding (in the Hall of Fame or privately — your call).
📨 How to report
Use the form below: your report is encrypted with PGP in your browser before sending — only we can read it. Give us enough to reproduce: steps, endpoint, impact.
🤖 AI tools
Welcome as assistants — but validate what you submit yourself. A reproducible report is gold; an unverified LLM copy-paste wastes both our time.
Trouble with the form? Direct contact: security@my-self.fr
Respect to all the curious. 🌱