About this policy
This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preference in how to submit any discovered vulnerabilities found within our systems.
If you make a good faith effort to comply with this policy during your security research, we will not take any legal action against you.
The following activities are not permitted against any system:
- denial of service (DoS/DDos) and spam
- social engineering (e.g. phishing) against our Department staff
- physical access attacks (e.g. attempting to access buildings)
- uploading malware, backdoors, webshells, or other ‘weaponised’ exploits that could degrade system security of affect other users
- attempt to access or manipulate accounts that do not belong to you (e.g. resetting passwords for other users)
- any attempt to modify or destroy data.
How to report a vulnerability
To report a vulnerability, please submit all reports to VulnerabilityDisclosure@dpird.wa.gov.au
To help address the issue as quickly as possible, your reports should:
- describe where the vulnerability was discovered and the potential impact of exploitation
- include enough detail so we can reproduce your steps. Screenshots and proof of concept code are helpful.
What happens next
- We will confirm we received vulnerability reports within 5 business days.
- We do not offer payment or public credit to security researchers for reporting potential or confirmed vulnerabilities.