1. 报告范围
- 影响本网站或公开服务页面的安全问题;
- 影响客户服务、授权流程或访问控制的漏洞;
- 实际或疑似未经授权访问、披露、修改或滥用广告数据;
- 与隐私、数据删除或授权撤销有关的事件。
2. 如何提交
请发送邮件至 security@hzinfinity.com。建议包含问题类型、受影响页面或服务、发现时间、复现步骤、潜在影响和安全的联系方式。
初次报告请不要包含:密码、访问 Token、Cookie、完整广告账户数据、无关个人信息或会扩大风险的利用代码。
3. 我们如何处理
- 确认:收到有效报告后确认收件,并提供可用于后续沟通的跟踪方式。
- 分级:根据影响范围、可利用性、数据敏感性和业务中断风险评估优先级。
- 调查:限制知情范围,收集必要证据并确认根因和影响。
- 缓解与修复:优先降低持续风险,再完成修复和验证。
- 通知与关闭:在适用法律、合同或平台要求下完成必要通知,并向报告人说明可公开的处理结果。
4. 善意报告
请避免破坏服务、访问不属于您的数据、影响其他用户、进行社会工程、拒绝服务或公开未修复细节。我们会对遵守上述边界的善意报告进行专业处理。
5. 紧急事件
如您认为事件正在造成持续的未授权数据访问,请在邮件主题中注明“URGENT / 紧急”,说明受影响范围和可安全执行的临时缓解建议。
1. Reporting scope
- Security issues affecting this website or public service pages;
- Vulnerabilities affecting customer services, authorization flows, or access controls;
- Actual or suspected unauthorized access, disclosure, modification, or misuse of advertising data;
- Privacy, deletion, or authorization revocation incidents.
2. How to submit
Email security@hzinfinity.com. Include the issue type, affected page or service, discovery time, reproduction steps, potential impact, and a safe contact method.
Do not include in the initial report: passwords, access tokens, cookies, complete advertising account data, unrelated personal information, or exploit code that expands risk.
3. How we handle reports
- Acknowledge: acknowledge a valid report and provide a tracking method for follow-up.
- Triage: assess priority based on scope, exploitability, data sensitivity, and business interruption.
- Investigate: limit need-to-know access, collect necessary evidence, and determine root cause and impact.
- Mitigate and remediate: reduce ongoing risk first, then complete and verify remediation.
- Notify and close: make required notifications under applicable law, contract, or platform rules, and share a reportable outcome with the reporter.
4. Good-faith reporting
Avoid disrupting services, accessing data that is not yours, affecting other users, social engineering, denial of service, or public disclosure of unresolved details. We handle good-faith reports that respect these boundaries professionally.
5. Urgent incidents
If an incident appears to be causing ongoing unauthorized data access, mark the subject “URGENT”, describe the affected scope, and include any safe temporary mitigation recommendation.