Report a vulnerability
Found a hole in PentestingHere itself? This is the channel. It goes straight to the admins, not to a shared inbox.
Safe harbour. Test in good faith and we will not come after you. Stay on your own accounts and data, stop at proof, and give us a chance to fix it before you publish.
Do not touch other people's data. A lot of what is stored here is under someone's NDA. If a bug exposes another researcher's private finding, take the smallest proof that shows it and stop.
Out of scope: denial of service, volumetric or automated scanning, social engineering of our staff or users, spam, and anything that degrades the service for other people.
No bounty yet. We are small and self-funded, so there is no money in this. What there is: a real reply from a person, a fix, and public credit if you want it.