πŸ”’ Security at pastes.io

At pastes.io, we take security seriously and implement measures to protect user data and maintain platform integrity.

πŸ›‘οΈ Security Measures

  • πŸ” Cloudflare Protection: We use Cloudflare to mitigate DDoS attacks and secure our infrastructure.
  • πŸ—οΈ Secure Data Handling: Pastes can be encrypted and password-protected for user privacy.
  • πŸ“œ Expiring Pastes: Users can set expiration times for pastes, reducing the risk of outdated or unwanted data exposure.
  • πŸ›‘ Abuse Prevention: We monitor for spam, phishing, and malware to maintain a safe environment.

🐞 Reporting Security Vulnerabilities

If you discover a security vulnerability on pastes.io, we encourage responsible disclosure.

πŸ“§ Report via Email: [email protected]

πŸ’‘ Note: We are a small company and currently unable to offer monetary rewards for security reports. However, we greatly appreciate your help in keeping our platform secure!

πŸ“Œ Scope

Our current scope includes:

  • *.pastes.io (all subdomains)
  • We also welcome reports for domains that may be associated with us but are not listed.

βœ… In-Scope Vulnerabilities

We are particularly interested in reports related to:

  • πŸš€ Remote Code Execution (RCE)
  • πŸ”“ Cross-site Scripting (XSS)
  • πŸ›‘οΈ Cross-site Request Forgery (CSRF)
  • πŸ“‚ Server-Side Request Forgery (SSRF)
  • πŸ“Š SQL Injection
  • πŸ“„ XML External Entity (XXE) Attacks
  • πŸ”‘ Access Control Issues (IDOR, Privilege Escalation, etc.)
  • πŸ› οΈ Exposed Admin Panels without strong protection
  • πŸ“‚ Directory Traversal Issues
  • πŸ” Local File Disclosure (LFD)
  • πŸ”’ User Data Leaks (Sensitive Information Disclosure)
  • 🚨 Known vulnerabilities in unpatched third-party software

🚫 Out-of-Scope Issues

  • πŸ” Information leakage that cannot be used for direct attacks
  • πŸ” Missing security headers that do not lead to a direct vulnerability
  • πŸ“‰ SPF/DMARC issues in non-email domains
  • πŸ“‘ Social engineering & physical attacks
  • πŸ“Š Reports from automated scanners/tools
  • 🌐 Distributed Denial of Service (DDoS) attacks
  • πŸ•΅οΈβ€β™‚οΈ Attacks requiring MITM or physical device access
  • πŸ›‘ Login/logout/low-impact CSRF
  • πŸ” Content spoofing & missing cookie flags
  • ⚑ SSL/TLS best practices
  • πŸ”„ Clickjacking/UI redressing
  • πŸ’» Flash-based vulnerabilities
  • πŸ“© Spam, email/SMS flooding
  • ⏳ 0-day vulnerabilities less than 30/60/90 days after patch release
  • πŸ› οΈ Third-party products outside of pastes.io control

πŸ” Security is our priority. Thank you for helping us keep pastes.io safe!