We're an offensive team, so we know how odd it would be not to have this page. If you've found a security vulnerability in n0hacks.com or any n0hacks-owned system, we want to know before anyone else does.
Email us at info@n0hacks.com with the subject "Vulnerability Report" and include: a clear description of the issue, steps to reproduce it, the potential impact you believe it has, and any proof of concept (screenshots, logs, a short video) that helps us verify it quickly.
We respond to legitimate reports within 72 hours, with an initial assessment and, where applicable, an estimated fix date.
Don't access, modify, or delete data that isn't yours.
Don't disrupt or degrade the site's service (no load testing, denial of service, or aggressive brute forcing).
Don't use findings to access more than strictly necessary to demonstrate the issue.
Give us a reasonable window to fix the issue before disclosing it publicly (we recommend 90 days, negotiable depending on severity and fix complexity).
You don't need to ask for explicit permission before starting your research: as long as you stay within these rules, we consider your research authorized in good faith.
Social engineering attacks against our team, physical attacks on our facilities, and purely theoretical findings without demonstrable practical impact are not covered by this program.
This program covers n0hacks.com and infrastructure directly operated by n0hacks. It does not cover our clients' systems: if you find something related to one of our clients during your research, report it directly to that client, not to us.
We don't have a formal paid bug bounty program right now, but we'll publicly credit (if you want) anyone who responsibly reports a valid vulnerability, and we always thank you the way a fellow professional deserves.