We actively support the following versions of NullScan with security updates:
| Version | Supported |
|---|---|
| 1.5.x | ✅ |
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take security seriously. If you discover a security vulnerability in NullScan, please report it responsibly.
Please do NOT create a public GitHub issue for security vulnerabilities.
Instead, please email us at: [email protected]
Include the following information:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Any suggested fixes (if available)
- Acknowledgment: We'll acknowledge receipt within 48 hours
- Assessment: We'll assess the vulnerability within 5 business days
- Timeline: We'll provide a timeline for fixes within 1 week
- Credit: We'll credit you in our security advisories (if desired)
When using NullScan:
- Permission: Only scan systems you own or have explicit permission to test
- Rate Limiting: Use appropriate concurrency settings to avoid overwhelming targets
- Network Isolation: Run scans from isolated environments when possible
- Log Security: Secure scan results that may contain sensitive information
- Updates: Keep NullScan updated to the latest version
- NullScan performs network scanning which may be detected by security systems
- Banner grabbing may expose service information
- High concurrency scans may trigger rate limiting or blocking
- Always comply with local laws and regulations
Thank you for helping keep NullScan secure! 🔒