Responsible Disclosure: From Finding to Hall of Fame

How I approach vulnerability disclosure: reproduce, document, report privately, and follow up. Lessons from UNESCO, CSIRT DKI Jakarta, and CSIRT Pati.

Finding a vulnerability is only half the work. Getting it fixed without burning bridges is the other half. Here is the workflow I follow for every report.

1. Reproduce Reliably

Before writing anything, I confirm the issue reproduces from a clean state:

  • Fresh session, minimal steps, no special tooling required by the reader.
  • Note the exact request/response pair that demonstrates impact.
  • Rule out false positives: expired sessions, cached data, and permission quirks.

If the triager cannot reproduce it in five minutes, the report stalls.

2. Document Impact Honestly

I describe what an attacker can actually do, not the worst imaginable scenario:

  • What data or action is exposed, and to whom.
  • Whether authentication is required, and what privilege level.
  • One realistic attack chain, not five speculative ones.

Overclaiming is the fastest way to lose credibility. I report only what I verified.

3. Report Through the Right Channel

  • Check for a published security policy or contact first.
  • For government CSIRT teams, use their official reporting channel with clear subject lines.
  • Include: summary, steps to reproduce, PoC, impact, and suggested remediation.
  • Never disclose publicly before the fix lands.

4. Follow Up Professionally

  • One polite follow-up if there is no response in a reasonable window.
  • Confirm the fix when asked, and confirm it properly with a retest.
  • Thank the team. Recognition programs like halls of fame exist because researchers stay professional.

What This Earned

This process led to formal acknowledgment in the UNESCO Hall of Fame and appreciation certificates from CSIRT Pemprov DKI Jakarta (Nov 2025) and CSIRT Kabupaten Pati (Feb 2026).

The lesson is simple: good reports get fixed, and fixed reports get recognized.

<- All posts