1Who we are
KSI Digital (PT Karunia Solusi Informatika) is a technology company based in Jakarta, Indonesia. Our security research team looks for vulnerabilities in internet-facing systems and reports them to the people who can fix them, through vulnerability disclosure and bug-bounty programs, and for clients who engage us to review their own systems.
2What this traffic is
It is authorized security research. We test only two kinds of system:
- Bug-bounty and vulnerability-disclosure programs whose published rules allow automated testing, and only within each program's stated scope, exclusions, testing window and rate limits.
- Client systems under written authorization. The authorization names who signed it and the agreement it belongs to, lists the assets we may test, and has a start and end date.
An authorization check runs before any request reaches a host. It refuses, and we do not test, when:
- the program's rules do not allow automated testing;
- the host is not in the program's scope, or is listed as excluded (exclusions always win);
- the program's testing window has not started or has ended;
- our copy of the program's rules has not been confirmed recently;
- we cannot tell exactly which program the rules belong to (the same program name on two platforms is treated as two programs, with two sets of rules);
- a host is explicitly listed as excluded, and an empty scope authorizes nothing;
- we test only the hostnames a program lists in scope, never a bare IP address or range, so an exclusion we cannot read as a hostname — an IP range, or a free-text note — describes nothing we would contact. We do not scan the IP addresses of programs sourced from public lists at all.
For client work, the check refuses any host outside the signed list of assets, any request outside the authorized dates, and any authorization without a named signatory. A withdrawn authorization takes effect from the next decision.
Our control plane records every authorization decision, including every refusal, in an append-only audit log.
3What our scanner does and does not do
What it does
- Finds hostnames within scope from public sources such as certificate transparency logs and passive DNS data. Names outside the authorized scope are discarded before they are resolved or contacted, and so are names whose DNS aliases point outside it.
- Checks whether an in-scope host answers over HTTP or HTTPS, and records the page title, the software it reports and its TLS certificate.
-
Runs detection checks from a public, open-source library. We use the
nuclei scanner with ProjectDiscovery's
nuclei-templates,
limited to HTTP checks, plus a small set of checks we write ourselves. Most checks read
what a site already serves publicly (version strings, headers, well-known file paths) to
identify software versions and configuration issues. A check for a specific known
vulnerability may send one crafted request and look for a tell-tale response, such as a
harmless marker value echoed back. Checks we write ourselves have a fixed shape: one GET
request for a public file (a WordPress plugin's
readme.txt) and a comparison of the version it reports. - Runs one check at a time. nuclei runs a single check against a single host at a time, gives each request 10 seconds, and does not retry a failed request.
- Tests by hostname, not by bare IP address, so requests reach the site that is in scope rather than whatever a shared server answers by default.
What it does not do
-
No intrusive checks. We exclude every library check tagged
intrusive,fuzz,dos,bruteforceordefault-login. The exclusion relies on the library's own tags: we do not review each of its thousands of checks individually, so if one of our checks behaved in a way you did not expect, please tell us and we will look at it. -
No password guessing and no attempts to sign in with default
credentials (the library's
bruteforceanddefault-loginchecks are excluded). - Only HTTP checks. The library's DNS, raw network, headless-browser and code check types are not run.
- No load testing or anything intended to slow down or disrupt a service.
- No out-of-band callbacks. nuclei's interaction server is switched off, so our checks do not ask your server to contact an outside service.
- No following redirects away from the address under test. One exception: a few library checks that send raw HTTP requests apply their own redirect setting. Any result from a host other than the one authorized is discarded.
- No internal addresses. When we look for hosts in a program's scope, a name that resolves to a private, loopback, link-local, cloud-metadata or other reserved address is dropped before it is contacted.
- No port checks unless a program authorizes the address. We check which ports are open on an IP address only when the program explicitly lists that address, or a range containing it, as in scope for testing. Even then we never check a reserved address, and we check only the 100 most common TCP ports. Otherwise we test only the web hostnames in scope.
Rate limits
By default we send no more than one request per second to a host. For client work we hold to the rate agreed with the client, and where a program states its own limit we stay within it. Retries count toward that limit. If a tool cannot run slowly enough to stay within it, the check is skipped rather than run faster.
People, not automation, decide what is reported
Automated checks only flag candidates. A researcher reviews each one, confirms the issue and prepares any proof of concept before anything is reported.
4How to recognize our traffic
User-Agent
Our detection checks identify themselves with this User-Agent header:
research-scanner/1.0 (+https://research.ksi-digital.com/about; research@ksi-digital.com)
The version number may change; the research-scanner/ prefix, the link to this
page and the contact address do not. Anyone can copy a User-Agent, so the source address
below is the more reliable signal.
Source IP addresses
https://research.ksi-digital.com/ips.txt lists the IP
addresses our scanning servers send from, one per line. It is the authoritative list and we
keep it current. Each scanning server has a fixed address, and each host is assigned to one
scanning server at a time, so you should see one of our addresses rather than many. The
list is empty at the moment because our scanning servers are not yet in service.
One exception: an occasional single header check — one HTTPS GET of a site's home page, without following redirects, after the same authorization check — is sent from Cloudflare's network instead. It carries the same User-Agent.
You are welcome to block the addresses in the list. We do not try to get around blocks.
5Ask us to stop, or report a problem
Email us with the hostnames or IP addresses concerned and, if you have them, a timestamp and the source address from your logs. We will stop testing the hosts you name and confirm by email. We aim to reply within two business days (Jakarta time, UTC+7). If our traffic is causing a problem right now, put URGENT in the subject and we will deal with it first.
If you run a bug-bounty or disclosure program and believe we have acted outside its rules, please also tell us through the platform, so the program has a record.
6How we disclose findings
- Findings in a bug-bounty or disclosure program go to the program owner through that platform's reporting process. Findings from client work go to the client.
- We never publish a finding before the owner has had a chance to fix it, and we follow each program's disclosure rules, including any rule against publishing at all.
- Each client's findings are kept separate from every other client's.
7Contact
Machine-readable contact details: /.well-known/security.txt.
Company information: ksi-digital.com.