Skip to content

Security: TEAMBCS/DooM-CANNON

Security

SECURITY.md

πŸ” Security Policy

πŸ“Œ Version

Security Policy Version: 4.0
Previous Version: 3.0


πŸ›‘οΈ Supported Versions

We actively maintain and provide security updates for the following versions:

Version Supported
4.0 βœ… Yes
3.0 ⚠️ Limited
< 3.0 ❌ No

🚨 Reporting a Vulnerability

If you discover any security vulnerability, please report it responsibly.

πŸ“© Contact Channels:

  • GitHub Issues (Private Disclosure Recommended)
  • Facebook Group: BANGLADESH CYBER SQUAD
  • Direct Developer Contact (if available)

πŸ“ Include in Report:

  • Vulnerability type (e.g., RCE, Injection, Logic flaw)
  • Steps to reproduce
  • Affected module/file
  • Proof of Concept (PoC) (if possible)
  • Suggested fix (optional but appreciated)

⏱️ Response Timeline

Stage Time
Initial Response 24–72 hours
Investigation 3–7 days
Patch Release Depends on severity

🎯 Scope

βœ… In Scope:

  • Core Python launcher (doom-cannon.py)
  • Go modules (*.go)
  • CLI interaction system
  • Input handling system
  • Headers / proxy handling

❌ Out of Scope:

  • Third-party libraries
  • Misconfigured user environments
  • Social engineering attacks
  • DDoS misuse complaints

⚠️ Responsible Use Policy

This tool is strictly for:

  • Educational purposes
  • Security research
  • Authorized testing

🚫 STRICTLY PROHIBITED:

  • Unauthorized attacks
  • Real-world disruption
  • Illegal activities

Any misuse is NOT the responsibility of the developers.


πŸ§ͺ Security Best Practices

Users are advised to:

  • Run the tool in controlled environments
  • Avoid using real targets without permission
  • Keep dependencies updated
  • Use VPN / sandbox environments for testing

πŸ† Bug Bounty / Credits

We appreciate responsible disclosure πŸ™Œ

  • Valid reports may receive:
    • Public credit
    • Contributor recognition
    • Future collaboration opportunities

πŸ”’ Disclosure Policy

  • Do NOT publicly disclose vulnerabilities before patch
  • Developers reserve the right to delay disclosure until fix is released

πŸ“’ Final Note

Security is a shared responsibility.
Help us improve this project by reporting issues responsibly ❀️


There aren't any published security advisories