Vulnerability Disclosure Policy
Stand: 2026-08-11
Security vulnerabilities on the website or in programs of gaijin.at can be reported confidentially to web@gaijin.at.
Communication is exclusively via email in German or English. Generally, every incoming report will be answered within one week. A response may be withheld if the reported vulnerability is not security-relevant, is already known, or cannot be reproduced.
Reports without a valid email address for follow-up questions may not be processed or may only be processed inadequately.
The report should include at least the following:- the URL or program in question
- a brief description of the vulnerability and its potential impact
- the exact steps for reproduction
- screenshots and/or text output
No legal action will be taken against the person reporting a vulnerability, provided this policy is followed. This does not apply if there is or was obvious criminal intent.
The following actions are not permitted:
- Use of automated scanning tools
- Attacks such as DoS/DDoS or brute-force attacks
- Use of malware such as viruses, Trojans, keyloggers, etc.
- Access to other users' data
- Modifying or deleting data on the server
- Exploiting a vulnerability beyond what is necessary for proof
- Publishing the vulnerability or the data obtained