Scanning of our servers is permitted with prior notice; we can block malicious activity, and vulnerabilities must be validated, website responsibility lies with the owner.
If you wish to carry out scans of our servers or associated websites, this is generally permitted.
However, for good coordination and operational stability we would appreciate being informed in advance of such scans. We also reserve the right to block activities that might affect the availability or performance of our systems.
If a scan should uncover potential vulnerabilities in our systems, we are, of course, happy to receive information about them. It should be noted, however, that we continuously perform extensive security scans ourselves and handle any findings in accordance with prevailing practice.
It is important to be aware that many automated scanning tools base their assessments on, for example, version numbers or open ports – without necessarily verifying whether the reported vulnerability actually exists. The tools often also do not take into account whether the relevant software has already been patched against known vulnerabilities. We therefore encourage any findings to be validated and reviewed critically before being reported to us.
Please note that identified vulnerabilities in websites that are merely hosted on our servers do not necessarily relate to our infrastructure or software. The responsibility for maintaining and securing those websites resides principally with the respective owner or developer. Enquiries regarding such findings should therefore be directed straight to the relevant party.
Article from the support category: General