Report requirements
- The incident must be real and have valid public evidence.
- Submit the affected public page or proof file itself. Exploit/XSS/SQLi payload URLs are not accepted as evidence.
- Automatic verification requires an exact visible attacker signature. Plain-text proof such as
Hacked by attacker can be verified directly when the submitted attacker matches; HTML pages are also checked for page context so news/articles are not mistaken for defacements. - Do not attack systems to create evidence.
- Pending targets are not published before verification.
- Administrators may reject or remove risky reports.