Skip to content

Security: 0x101-Cyber-Security/NetLock-RMM

SECURITY.md

Security Research & Responsible Disclosure

Please do not use AI tools or other methods to analyze the security of the code published in our GitHub repositories or report potential vulnerabilities based on that code.

Our closed source version has evolved significantly beyond the now outdated GitHub codebase. The publicly available code reflects an early prototype of NetLock RMM and no longer represents the architecture or security posture of the current product.

If you're interested in security research or penetration testing, we welcome you!

Simply deploy a self hosted instance of NetLock RMM through our Members Portal. You are welcome to conduct penetration testing against your own deployed instance as extensively as you like.

Please note the following scope restrictions:

  • Testing must be limited to your own self-hosted NetLock RMM instance.
  • Do not target or attack our cloud infrastructure.

Vulnerability Rewards

If you discover a vulnerability that could compromise a NetLock RMM server instance, we encourage you to report it to us. Examples include remote code execution (RCE), authentication bypasses, or other vulnerabilities that could lead to unauthorized access or server compromise.

We offer rewards based on the severity of the vulnerability, including:

  • Monetary rewards proportional to the severity and impact of the vulnerability.
  • A lifetime self-hosted NetLock RMM license with unlimited devices for one server.

We appreciate the time and effort security researchers invest in helping us improve NetLock RMM's security. Responsible vulnerability disclosures are welcome and valued.

Please send your findings to: nico.mak@0x101-cyber-security.de

There aren't any published security advisories