If you have found a security problem in Neda eCampus, we want to hear about it from you before we hear about it from anyone else. This page tells you how to reach us, what we will do, and what we ask of you in return.
How to report
Email info@neda-els.com with “Security” in the subject line. A report is most useful to us when it contains:
- the address of the page or endpoint concerned;
- what you did, in enough detail that we can repeat it;
- what happened, and why you believe it is a problem;
- the date and rough time, so we can find it in our logs.
Please write in English or German. Screenshots and short recordings help. You do not need to prove the full impact of an issue before telling us about it — a clear description of something that looks wrong is worth more to us than a polished exploit.
The same details are published in machine-readable form at /.well-known/security.txt, following RFC 9116.
What we commit to
- We will acknowledge your report within three working days.
- We will give you our first assessment — whether we can reproduce it, and how serious we think it is — within ten working days.
- We will keep you informed while we work on it, and tell you when it is fixed.
- We will credit you by name when we publish the fix, if you would like us to. If you would rather stay anonymous, that is equally fine.
- We will not take legal action against you, and will not ask anyone else to, for research carried out in good faith under this policy.
We are a small team. Those are the timescales we can actually keep rather than the shortest ones we could write down. If something is being actively exploited, say so in the subject line and we will drop everything.
What we ask of you
- Give us a reasonable chance to fix the problem before you tell anyone else about it. Ninety days is the norm we work to, and we will usually be much faster.
- Use only your own accounts and your own data. If you come across somebody else’s personal data, stop, do not save it, and tell us what you saw.
- Take no more than you need to demonstrate the issue. Do not download databases, do not modify or delete anything, and do not keep access once you have shown the point.
- Tell us if you used automated tooling, and which. It lets us tell your traffic apart from a real attack in the same logs, which is worth a great deal to us and costs you one sentence.
In scope
Everything we run:
nedaecampus.com— this site, and the course cataloguelearn.nedaecampus.com— the Moodle learning platformauth.nedaecampus.com— sign-in and accountscreator.nedaecampus.com— the creator workspaceopenedx.nedaecampus.com— the Open edX study platform
Out of scope
- Anything that degrades the service for other people — denial of service, load testing, or automated scanning heavy enough to be felt.
- Social engineering of our staff, our learners or our suppliers, and any form of physical access attempt.
- Findings from a scanner with no demonstrated impact — a missing header or a weak cipher suite on its own. Tell us anyway if you think it matters, but say why.
- Systems we do not run. Our payment processing, mail and DNS are third-party services; report issues in those to the provider concerned.
There is no bug bounty
We do not pay for vulnerability reports, and we would rather say so plainly here than let you find out after the work. What we offer is a fast, honest answer from someone who will actually fix it, and public credit if you want it.
If your own account is affected
This page is for reporting flaws in the platform. If you think your own account has been accessed by someone else, that is not a research report and should not wait ninety days — write to info@neda-els.com straight away and say so, or use the contact form.
