| Version | Supported |
|---|---|
| 1.0.0 | 🟢 |
| < 1.0 | 🔴 |
-
Reporting Process
- Email security issues to: eric.moghioros000@gmail.com
- Include
lanmess security vulnerabilityin the subject line - Provide detailed information about the vulnerability
- If possible, include steps to reproduce the issue
-
What to Expect
- You will receive acknowledgment of your report within 48 hours
- We will investigate and provide regular updates on the status
- Once fixed, you will be notified and can verify the solution
-
Guidelines
- Please do not disclose security vulnerabilities publicly
- Do not test vulnerabilities on production systems
- Provide sufficient time for us to address the issue before any disclosure
-
Known Security Considerations
- LanMess uses UDP broadcast for communication
- Messages are not encrypted by default
- The program operates on port 12345
- Local network traffic can be intercepted
-
Scope
- Network communication security
- User input validation
- System resource usage
- Installation script security
- Configuration file permissions
- Use
lanmessonly on trusted local networks - Keep your system and the application up to date
- Use a firewall to control UDP broadcast traffic
- Be cautious when sharing sensitive information
- Monitor system resources while using the application
We are committed to maintaining the security of lanmess. Check this section for security-related updates and patches.
- 2025-02-05: Initial security policy established
Thank you for helping keep lanmess and its users safe!