Skip to content

Security: TEAMBCS/Site-HOUND

Security

SECURITY.md

πŸ” Security Policy

πŸ“Œ Overview

The Site HOUND project takes security seriously. We encourage responsible disclosure of vulnerabilities to ensure the safety of users and the integrity of the project.


πŸ›‘οΈ Supported Versions

The following versions of Site HOUND are currently supported with security updates:

Version Supported
v2.0.0+ βœ… Yes
<v2.0.0 ❌ No

⚠️ Always use the latest version to stay protected.


🚨 Reporting a Vulnerability

If you discover a security vulnerability, please do not disclose it publicly.

Instead, report it responsibly:

πŸ“© Contact Methods

  • πŸ“§ Email: bcs.team.oficial@gmail.com
  • πŸ’¬ GitHub Issues: Use private reporting (if available)
  • πŸ” Facebook (Private Message): Bangladesh Cyber Squad

πŸ“‹ What to Include

To help us investigate quickly, include:

  • πŸ“Œ Description of the vulnerability
  • 🎯 Affected component (module, function, feature)
  • πŸ” Steps to reproduce
  • πŸ’₯ Potential impact
  • πŸ“Ž Proof-of-concept (if possible)

⏱️ Response Timeline

Stage Time
Initial response within 24–72 hours
Investigation 3–7 days
Fix release depends on severity

We aim to respond as quickly as possible.


πŸ”’ Responsible Disclosure Policy

We follow a responsible disclosure approach:

  • ❌ No public disclosure before fix
  • βœ… Coordinated disclosure after patch
  • 🀝 Credit will be given (if requested)

⚠️ Scope

This policy applies to:

  • Core fuzzing engine (site-hound.py)
  • Wordlist processing system
  • Header spoofing engine
  • Async request handling
  • Output & logging system

🚫 Out of Scope

The following are not considered vulnerabilities:

  • Misuse of the tool
  • Scanning without permission
  • Target-side vulnerabilities
  • Rate limiting or blocking by target servers

🧠 Security Best Practices for Users

  • βœ” Use only on authorized targets
  • βœ” Avoid aggressive scanning on production systems
  • βœ” Use rate limiting to prevent disruption
  • βœ” Respect legal and ethical boundaries

βš–οΈ Legal Notice

This tool is intended for educational and authorized security testing only.

The maintainers are not responsible for:

  • misuse of the tool
  • illegal activities
  • damage caused by improper usage

πŸ™ Acknowledgements

We appreciate responsible security researchers who help improve this project.


πŸ”₯ Note

β€œSecurity is not a feature β€” it is a responsibility.”


There aren't any published security advisories