Skip to content

Security: a-bonfim-tech/thm-guided-pentest-web

Security

SECURITY.md

Security Policy

Scope

This repository documents an authorized TryHackMe web application penetration testing lab. It is a portfolio and learning artifact, not an authorization to test real third-party systems.

The repository should not contain:

  • Active credentials
  • Session tokens
  • Flags or answer keys
  • Private personal data
  • Live third-party targets
  • Reusable exploit instructions against real systems

Reporting a Concern

Open a GitHub issue if you identify:

  • Sensitive lab answers or flags
  • Credentials, tokens, or session material
  • Unsafe instructions that could be reused against real systems without authorization
  • Personal data or third-party confidential data
  • Incorrect statements about authorization, scope, or methodology

Do not include sensitive values in public issue text. Describe the affected file path and the general issue category.

Triage Process

Reports are handled in this order:

  1. Preserve the report and affected file path.
  2. Confirm whether the content is sensitive, unsafe, or inaccurate.
  3. Remove or sanitize the affected material.
  4. Update the README, NOTICE, or evidence notes if the scope needs clarification.
  5. Record the correction in commit history.

Ethical Use

The techniques discussed here are for authorized training and defensive learning only. Do not use this repository as authorization to test systems owned by others.

There aren't any published security advisories