diff --git a/README.md b/README.md index 1c2d25d..4293817 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,11 @@ ## Disclaimer :warning: -**The authors of this document take no responsibility for correctness. This project is merely here to help guide security researchers towards determining whether something is vulnerable or not, but does not guarantee accuracy. This project heavily relies on contributions from the public; therefore, proving that something is vulnerable is the security researcher and bug bounty program's sole discretion. Furthermore, it is important to clarify that this project does not aim to identify or disclose bypasses to security measures implemented by various services. Instead, it is expected that such bypasses be reported directly to the affected service for appropriate action. Finally, it is worth noting that some bug bounty programs may accept dangling DNS record reports without requiring proof of compromise.** +**The authors of this document take no responsibility for correctness. This project is merely here to help guide security researchers towards determining whether something is vulnerable or not, but does not guarantee accuracy. This project heavily relies on contributions from the public; therefore, proving that something is vulnerable is the security researcher and bug bounty program's sole discretion.** + +**Furthermore, it is important to clarify that this project does not aim to identify or disclose bypasses to security measures implemented by various services. Instead, it is expected that such bypasses be reported directly to the affected service for appropriate action.** + +**Finally, it is worth noting that some bug bounty programs may accept dangling DNS record reports without requiring proof of compromise.** ## What is a subdomain takeover?