# Security contact for looknbooks.com (RFC 9116) # If you have found a vulnerability, please tell us before telling anyone else. Contact: mailto:security@looknbooks.com Expires: 2027-08-04T00:00:00.000Z Preferred-Languages: en Canonical: https://looknbooks.com/.well-known/security.txt Policy: https://looknbooks.com/terms.html # Scope # In scope: looknbooks.com and www.looknbooks.com # Out of scope: the third-party services this site embeds -- report those to # their owners: Travelpayouts/Aviasales (the flight widget), # Cloudflare (hosting), OpenStreetMap/Nominatim, Unsplash. # # This is a static site: HTML, CSS and JavaScript served from object storage. # There is no application server, no database, no user accounts and no # authentication, so classes such as SQL injection, auth bypass and IDOR do # not apply. What IS interesting to us: anything that executes script in the # looknbooks.com origin, anything that rewrites a booking hand-off link to a # destination we did not intend, and anything published from the deploy root # that should not be public. # # Please do not run automated scanners that degrade the service for real # travellers, and please do not access or modify data that is not yours. # Report in good faith and we will not pursue you.