hack.fish

security testing & responsible disclosure

↓ seeing traffic from us? read why

why you might see us

hack.fish is used for security testing and research. That traffic is one of two things:

  • penetration tests, commissioned by the owner of the systems being tested;
  • independent security research, where we look for vulnerabilities in public-facing systems and report what we find to the owner through responsible disclosure.

In both cases we act in good faith: we do not try to disrupt services, we do not access or keep more data than needed to show a problem exists, and we report findings to the owner rather than publish them.

If your logs show scans, requests or login attempts from hack.fish or the addresses below, it is most likely one of these.

unexpected traffic? tell us

If you did not expect it, or think it hit something out of scope, email abuse@hack.fish. Please include:

  • the source IP address
  • timestamps, with time zone
  • the target host, IP or URL
  • relevant log lines, if you can share them

We look into every report, stop testing your systems if you ask us to, and reply. If we found something on your systems, we will tell you what and how to fix it.

contact

our addresses

Testing traffic originates from 173.212.222.53 (hack.fish).