Security
Report a security problem.
If you have found something that lets one hosting account reach another, lets the web tier reach root, or lets a release be forged, that is the kind of thing this page is for, and we want to hear it.
Where to send it
A disclosure address is not published yet. KLYRN is in beta and does not yet have a coordinated-disclosure address or policy. Until it does, sign in at my.klyrn.com with the account you installed with and open Beta feedback in the sidebar. It reaches the same people. Please do not include keys, passwords or customer data in the report.
What to include
Enough for somebody to reproduce it. A report we cannot reproduce is a report we cannot fix, and the round trip asking for detail is the slowest part of every disclosure.
- What you did, in order, and what happened.
- The KLYRN version:
klyrn version, or the footer of the panel. - Whether it needs an account, and which role: nobody, a customer, a reseller, an administrator.
- What an attacker gets out of it. "Reads another account's files" is a different problem from "crashes the panel".
- A proof of concept if you have one, against your own server.
What never to send
Nobody at KLYRN needs any of these to investigate a report, and a report is not a secure channel. If a finding seems to require one, say so and we will arrange something rather than have you paste it into an email.
- Your master key or any private key.
- Backup encryption keys.
- Database passwords, or a
wp-config.php. - API tokens or panel passwords.
- Another person's data. If a bug exposed somebody else's files, tell us that it did. Do not send them.
klyrn doctor -bundle produces a support bundle that is scrubbed of credentials on the way in, and it
never reads a private key, the database, or a customer file. It is the safe thing to attach. Read it first: it is
your server.
What we can and cannot promise
KLYRN is in beta and run by a small team. We will acknowledge your report and tell you what we find. We have not published a disclosure policy, a response-time commitment, a safe-harbour statement or a bounty, and this page is not going to imply one exists: you should know exactly where you stand before you spend your time.
What we do commit to: we will not threaten you for testing your own server, and we will credit you when a fix ships if you want to be credited.
Not a security problem?
For anything that is not a vulnerability (a site that will not load, a certificate that will not issue, a
migration that went sideways), start with
Troubleshooting, which is organised by symptom, and
klyrn doctor, which examines the whole server and names causes rather than symptoms.