diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md index d496f49..47bd02f 100644 --- a/CODE_OF_CONDUCT.md +++ b/CODE_OF_CONDUCT.md @@ -20,6 +20,7 @@ data, knowingly false claims, and requests for unauthorized exploitation are not welcome. Maintainers may edit, hide, reject, or remove contributions that violate these expectations and may restrict participation when necessary. -Report conduct concerns privately through the repository owner's available -GitHub contact or security-advisory channel. Good-faith reports will be handled -with discretion. +Report conduct concerns privately through the repository owner's +[LinkedIn](https://www.linkedin.com/in/mahdikarzari), +[Telegram](https://t.me/QM4RS), or GitHub security-advisory channel. Good-faith +reports will be handled with discretion. diff --git a/README.md b/README.md index e198aad..a59dd2a 100644 --- a/README.md +++ b/README.md @@ -266,6 +266,15 @@ See [CHANGELOG.md](CHANGELOG.md), [CONTRIBUTING.md](CONTRIBUTING.md), and [GitHub publishing checklist](docs/GITHUB_PUBLISHING.md) for the first public push, branch protection, topics, and release setup. +## Contact + +- LinkedIn: [Mahdi Karzari](https://www.linkedin.com/in/mahdikarzari) +- Telegram: [@QM4RS](https://t.me/QM4RS) + +For security-sensitive reports, start with GitHub's private vulnerability +reporting when available. If that channel is unavailable, use one of the contact +methods above and avoid sending secrets or sensitive proof in the first message. + ## Acknowledgements FridaBox stands on years of work by the Android instrumentation and diff --git a/SECURITY.md b/SECURITY.md index 03a445c..776d028 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -12,6 +12,11 @@ this repository when it is available. Do not open a public issue for a flaw that could expose imported APKs, JavaScript agents, device data, signing material, or an unintended network listener. +If private vulnerability reporting is unavailable, request a private reporting +channel through [LinkedIn](https://www.linkedin.com/in/mahdikarzari) or +[Telegram](https://t.me/QM4RS). Do not include credentials, private APKs, +proprietary agents, or an operational exploit in the initial message. + Include: - affected commit/version and Android build;