#vulnerabilitydisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vulnerabilitydisclosure, aggregated by home.social.
-
Good disclosure policies often hide from automation: behind bot protection, or deep in a help-center sitemap.
lookup.disclose.io follows the legal and help branches of a site's sitemap, follows an owner-endorsed security portal on the same domain, and uses human-reviewed evidence when an official page blocks bots.
Bunnings, TCL, and Motorola Solutions publish a policy. lookup reaches it. A current security.txt still ranks first.
-
lookup.disclose.io runs inside the tools you already use, thin clients over one API:
dio-lookup CLI (npm), Caido plugin, Burp and ZAP extensions, Chrome extension, Nmap NSE, Nuclei templates, a hosted MCP server in the MCP registry, and a JSON API with OpenAPI 3.1 and llms.txt.
Since August 13 the Burp, ZAP, Caido, and Chrome plugins are route-aware: contacts grouped the way the site groups them, owner route first.
-
Testing out the new author attribution feature: https://skyplabs.com/posts/xss-iban-secured-transfer/
#Security #Web #WebSecurity #XSS #VulnerabilityDisclosure #Notary #Mastodon #Fediverse