Skip to content

Security: EPTLLC/brs-xss

Security

SECURITY.md

Security Policy

Project: BRS-XSS (Brabus Recon Suite - XSS Module)
Company: EasyProTech LLC (www.easypro.tech)
Contact: https://t.me/EasyProTech

Supported Versions

Version Supported
2.1.x Yes
2.0.x No
1.x.x No

Reporting a Vulnerability

RESPONSIBLE DISCLOSURE ONLY

If you discover a security vulnerability in BRS-XSS, please report it responsibly:

Contact Methods

What to Include

  1. Vulnerability Description: Clear description of the issue
  2. Steps to Reproduce: Detailed reproduction steps
  3. Impact Assessment: Potential security impact
  4. Proof of Concept: Safe demonstration (if applicable)
  5. Suggested Fix: Your recommendations (optional)

What NOT to Do

DO NOT:

  • Publicly disclose the vulnerability before we've had a chance to fix it
  • Test on systems you don't own or have explicit permission to test
  • Access, modify, or delete data belonging to others
  • Perform DoS attacks or resource exhaustion tests
  • Use social engineering techniques

Our Commitment

WE WILL:

  • Acknowledge receipt within 48 hours
  • Provide regular updates on our progress
  • Credit you in our security advisories (if desired)
  • Work with you to understand and resolve the issue
  • Notify you when the issue is resolved

Disclosure Timeline

  1. Day 0: Vulnerability reported
  2. Day 1-2: Initial response and triage
  3. Day 3-30: Investigation and fix development
  4. Day 30-90: Testing and release preparation
  5. Day 90+: Public disclosure (coordinated)

Security Best Practices

When using BRS-XSS:

  • Authorization Required: Only test systems you own or have explicit permission to test
  • Safe Mode: Use --safe-mode for production environments
  • Rate Limiting: Respect target server resources with appropriate delays
  • Legal Compliance: Ensure compliance with local laws and regulations

WAF Evasion Features

WARNING: BRS-XSS includes WAF bypass capabilities intended for legitimate security testing only.

Responsible Use Policy:

  • Only use on systems you own or have written authorization to test
  • Do not use to bypass security controls on systems without permission
  • Ensure compliance with applicable laws and regulations
  • Report any discovered vulnerabilities through proper channels

Legal Notice

This tool is provided for legitimate security testing purposes only. Users are responsible for ensuring their use complies with all applicable laws and regulations. EasyProTech LLC assumes no liability for misuse of this software.


Last Updated: Sun 26 Oct 2025 14:20:00 UTC
Version: 2.1.0

There aren’t any published security advisories