SECURITY
Hall of Fame
Security researchers who found and responsibly reported vulnerabilities in Raw Strix. Thank you for helping keep every event and every player safe.
NO ENTRIES YET
Find something we missed? Your name could be the first one here.
Report a vulnerability
A security contact address will be published here shortly. We will acknowledge your report within 3 working days and keep you updated until it is fixed.
In scope
- ✓rawstrix.com and its pages
- ✓Event sites on *.rawstrix.com (the platform itself, not the challenges)
- ✓The organiser panel at panel.rawstrix.com
- ✓Our APIs and anything that could expose another organiser's or player's data
Out of scope
- ×CTF challenges themselves: they are meant to be broken. Solve them for the points.
- ×The demo at demo.rawstrix.com resetting or showing example data
- ×Denial of service, load testing or anything that disrupts a live event
- ×Social engineering, phishing or physical attacks on our team or customers
- ×Reports from automated scanners without a working proof of concept
- ×Missing best-practice headers or settings with no demonstrable impact
Rules
- ▸Only test against your own accounts and events. Never access, change or delete other people's data.
- ▸Stop and report as soon as you have shown the issue. Do not pivot further or keep access.
- ▸Give us reasonable time to fix the issue before you talk about it publicly.
- ▸Include clear steps to reproduce, the impact and, if you can, a proof of concept.
Valid reports are credited here with your name or handle and an optional link. We do not run a paid bug bounty at the moment.