Terms of use and limitation of liability.
1dayexploit ("we", "us") operates 1dayexploit.com and alim.1dayexploit.com, including the ÂLIM analysis engine and everything published on either site. This notice governs your use of them. If you do not accept it, do not use the sites.
Everything we publish exists for education, defence and security research. Nothing here is legal advice, nor security advice for your particular environment, nor a recommendation to take any specific action.
Nothing here is permission.
We publish technical detail about vulnerabilities in third-party software, including working proof-of-concept code. It is published so that defenders can understand and test their own systems, and so that other researchers can check our findings rather than take our word for them.
Nothing on these sites authorises you to access, test, disrupt or interfere with any system. Authorisation can come only from the party that controls the system, and it should be explicit and in writing. Use what we publish against systems you own, or systems you hold that authorisation for, and nothing else.
Unauthorised access to a computer system is a criminal offence virtually everywhere. Articles 243 to 245 of the Turkish Penal Code (law no. 5237), the Computer Fraud and Abuse Act in the United States, the Computer Misuse Act in the United Kingdom and the national laws implementing EU Directive 2013/40 are examples rather than a complete list. Curiosity, or an intention to check whether something is secure, is not a defence under any of them.
You are responsible for the law that applies to you, both where you are and where the system you touch is. That is not affected by anything in this notice and it is not something we can waive on your behalf. Anyone acting without authorisation does so on their own responsibility. We do not endorse it, we do not assist it, and we answer no requests for help with it.
What we publish, and when.
Every vulnerability we write about is already public before we touch it. The CVE record, the vendor advisory and, in most cases, the patch commit are published by other parties first, and a patch is itself a public description of where the flaw was. Our analyses are our own work on top of material that is already in the open, published after a fix exists. We do not put capability into the world that was not already available to anyone who read the patch.
- Proof-of-concept code is published only after a fix exists. For already-disclosed vulnerabilities that means after the vendor has shipped the patch. We do not publish working code for anything still unfixed.
- For flaws we find ourselves, the maintainer comes first. We report privately and publish an advisory once there is a fix, or once the maintainer has declined to issue one and a reasonable period has passed.
- We do not sell vulnerabilities and we do not hand out exploits privately on request.
- We do not help anybody attack a system. We take no requests for software that has no fix, we name no live targets, we do not extend or adapt a published proof-of-concept for anyone, and we answer no question whose only purpose is reaching a system the asker has no right to.
- Failed attempts are published too. Where we cannot reproduce a published vulnerability we say so and show the work. That is a statement about what our tests showed under the conditions we tested, not a claim that no vulnerability exists.
Analyses are produced by automation.
ÂLIM is an automated engine and parts of its output are machine-generated. Every analysis we publish has been executed against both a vulnerable and a patched build, which is what stops a plausible-looking claim from reaching the site untested. It is not a guarantee. Automation misreads code, versions get attributed wrongly, and a test that passes can still be testing the wrong thing.
Treat every analysis as a starting point to verify against your own systems, not as an authoritative statement about them. Decisions about patching, exposure or risk in your environment remain yours.
No warranty.
The sites and all content on them are provided "as is" and "as available", without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy or non-infringement. We do not warrant that the sites will be uninterrupted, secure or error-free, or that what is published on them is complete, current or correct.
Vulnerability records, severity scores and affected-version ranges come in part from third parties, among them the NVD, MITRE and vendor advisories. Those sources contain errors, and we reproduce them without independent verification unless an individual analysis states otherwise.
Limitation of liability.
To the fullest extent permitted by applicable law, we are not liable for any loss or damage, whether direct, indirect, incidental, special, consequential, punitive or exemplary, including loss of profit, data, goodwill or business interruption, arising out of or connected with your use of the sites, your reliance on anything published on them, or any use or misuse of the code, techniques or information we publish, whether by you or by anybody else. This applies however the liability arises, in contract, tort, negligence or otherwise, and whether or not we had been advised that such loss was possible.
Nothing in this notice excludes or limits liability that cannot lawfully be excluded or limited.
Third-party names and links.
Vendor, product and project names appear here only to identify the software an analysis concerns. All trademarks belong to their respective owners. Their use does not imply any affiliation with, sponsorship by or endorsement from those owners, and none of them has reviewed or approved our work. Links to external sites are given for reference; we do not control them and are not responsible for what they contain.
Corrections and removal.
If an analysis is factually wrong, misattributes a version, or discloses more than it should, tell us. If you maintain the software and need something held back, tell us that too. Write to [email protected], encrypted with our PGP key if you prefer. We correct errors on the record rather than silently, and we will discuss timing on anything sensitive.
Information we hold.
If you request an analysis through ÂLIM we store the email address you submit and the CVE you asked about, for one purpose: running that analysis and telling you when it is published. We do not sell it, pass it on, or use it to market anything. Ask at [email protected] and we delete it.
Governing law and changes.
We operate from Türkiye. This notice, and any dispute about the notice itself or about our own conduct, is governed by Turkish law, and the courts of Türkiye have jurisdiction. That choice concerns this document and nothing wider.
It does not displace rights you hold under the law where you live that cannot be contracted away, and where such a rule applies it prevails over the corresponding term here. Nor does it change which criminal law applies to what you do, which is covered in section 01 and depends on where you are and what you touch, not on this notice.
If any part of this notice is held unenforceable in a given jurisdiction, that part is treated as narrowed to the extent needed, or removed, and the rest continues to apply. We may update the notice; the date at the top of the page shows when it last changed, and continued use of the sites after a change means you accept the updated version.
Questions about any of the above: [email protected].