How to report
If you found a way to get around overlay.win’s security, please tell us before you tell anyone else. Write to [email protected]. Say what you found, the steps to reproduce it (a few lines is enough), and what you think an attacker could do with it. Please do not include other people’s data in the report.
overlay.win is run by one developer. We aim to answer within 7 days and to fix serious problems as fast as we safely can. We will tell you when it is fixed, and credit you if you want.
What is in scope
- The website and API at overlay.win, including sign-in, sessions, licences, devices, downloads and the Marketplace.
- The loader and the app (
overlay.win.exe), including how they sign in, update and install plugins. - The signing of releases, the plugin catalog and plugin packages.
What is out of scope
- Denial-of-service, spam, or anything that needs a lot of traffic.
- Social engineering of anyone, physical attacks, and attacks on other people’s accounts or PCs.
- Problems that need an already-compromised PC or Windows account (malware running as the same user can do what that user can do).
- Antivirus warnings about the loader or app, and missing hardening headers on pages that carry no account data.
- Old builds that the server already refuses.
Ground rules
- Use your own account and your own PC. Do not read, change or delete anyone else’s data.
- Stop as soon as you have shown the problem; do not keep going to see how far it goes.
- Give us reasonable time to fix it before you publish anything.
If you follow these rules we will not take legal action against you for research in good faith. There is no cash reward programme at the moment.
The machine-readable file
The same contact details are published at /.well-known/security.txt.