Skip to content

Security: Xonotic-Devs/xonotic

Security

SECURITY.md

๐Ÿ”’ Security Policy

๐Ÿ›ก๏ธ Supported Versions

We actively support security updates for the following versions of Xonotic:

Version Supported
0.8.5 โœ… Yes
0.8.x โœ… Yes
0.7.x โŒ No
< 0.7 โŒ No

๐Ÿšจ Reporting a Vulnerability

๐ŸŽฎ Game Security Issues

If you discover a security vulnerability in Xonotic, please report it responsibly:

๐Ÿ“ง Contact Methods

  • Email: security@xonotic.org
  • Discord: Direct message to @Administrators
  • Private: Do NOT create public issues for security vulnerabilities

๐Ÿ“‹ Report Format

Please include:

  • Description: Clear explanation of the vulnerability
  • Impact: How it affects players/servers
  • Reproduction: Step-by-step instructions
  • Environment: Game version, OS, server setup
  • Evidence: Screenshots, logs, or video proof

๐Ÿš€ Response Timeline

Stage Timeline Action
Initial Response 24-48 hours Acknowledge receipt
Investigation 1-7 days Analyze and verify
Fix Development 1-14 days Create and test patch
Release 1-3 days Deploy security update
Disclosure After fix Public security advisory

๐Ÿ” Security Scope

โœ… In Scope

  • Server Exploits: Remote code execution, crashes
  • Client Vulnerabilities: Code injection, file access
  • Network Issues: DDoS amplification, packet manipulation
  • Authentication Bypass: Server admin circumvention
  • Data Leaks: Personal information exposure
  • Cheating Infrastructure: Wallhacks, aimbots at engine level

โŒ Out of Scope

  • Gameplay Balance: Weapon strength, map design
  • Standard Cheats: Typical FPS cheating (use anti-cheat)
  • Social Engineering: Player impersonation
  • Third-party Mods: Custom modifications
  • Legacy Versions: Unsupported game versions
  • Client-side Configs: Player preference exploits

๏ฟฝ๏ฟฝ๏ธ Security Best Practices

๐ŸŽฏ Server Administrators

  • Update Regularly: Always run latest Xonotic version
  • Monitor Logs: Watch for suspicious activity
  • Limit Permissions: Restrict admin access
  • Backup Data: Regular server data backups
  • Network Security: Use firewalls and DDoS protection

๐ŸŽฎ Players

  • Official Downloads: Only download from xonotic.org
  • Verify Checksums: Check file integrity
  • Avoid Suspicious Servers: Don't join untrusted servers
  • Report Cheaters: Use in-game reporting
  • Update Game: Keep client updated

๐Ÿ† Security Hall of Fame

We recognize security researchers who help keep Xonotic safe:

๐Ÿฅ‡ 2024 Contributors

  • [Reporter Name] - Found critical RCE vulnerability
  • [Researcher] - Discovered authentication bypass
  • [Community Member] - Reported server crash exploit

Want to be listed? Report a valid security issue!

๐Ÿ“‹ Vulnerability Categories

๐Ÿšจ Critical (CVSS 9.0-10.0)

  • Remote code execution
  • Full system compromise
  • Mass server takeover

โš ๏ธ High (CVSS 7.0-8.9)

  • Privilege escalation
  • Data extraction
  • Service disruption

๐Ÿ“ข Medium (CVSS 4.0-6.9)

  • Information disclosure
  • Limited DoS attacks
  • Authentication issues

๐Ÿ” Low (CVSS 0.1-3.9)

  • Minor information leaks
  • Edge case crashes
  • Configuration issues

๏ฟฝ๏ฟฝ Security Resources

๐Ÿ“š Documentation

๐Ÿ›ก๏ธ Tools

  • Log Analyzer: Monitor server security
  • Traffic Inspector: Network packet analysis
  • Integrity Checker: Verify game files

๐Ÿ“ž Emergency Contact

For critical security issues requiring immediate attention:

๐Ÿ™ Acknowledgments

Thanks to the gaming security community for keeping Xonotic safe and the competitive FPS scene secure.


Security is everyone's responsibility in competitive gaming! ๐ŸŽฎ๐Ÿ”’

There arenโ€™t any published security advisories