LinkedIn-px-ads
logo
Loading...
logo

OFZA Self Host Bug Bounty Program

Program Description

The OFZA team acknowledges the critical role that security researchers play in safeguarding our community. We strongly encourage the responsible disclosure of security vulnerabilities through our Bug Bounty Program, as outlined on this page.

Program Rule

  • Check the list of domains that are in scope for the Bug Bounty program.
  • Make a good faith effort to avoid privacy violations, destruction of data interruption, or degradation of our businesses, including Denial of Services attacks.
  • Not exploit the vulnerability in any way, including through making it public or by obtaining a profit (other than a reward under this Program).
  • Please do not publicly disclose any vulnerabilities without our consent. We will not approve Public Disclosure requests until the vulnerability has been resolved.
  • Do not attempt non-technical attacks such as social engineering, phishing, or physical attacks against our employees, users, or infrastructure.
  • Do not use scanners or automated tools to find vulnerabilities. They are noisy and we may ban your IP address.
  • Submit only one vulnerability per submission unless you need to chain vulnerabilities to provide impact regarding any of the vulnerabilities.
  • In case we receive duplicate reports of a specific vulnerability, only the first report is eligible for a reward.
  • By submitting a bug, you agree to be bound by the rules.

 

You can email vulnerabilities/bugs to us at [email protected]

Program Scope

https://ofza.com/en

 

 

Submit a vulnerability

OUT OF SCOPE – WEB VULNERABILITIES

  • Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
    • Vulnerabilities in third-party applications
    • Assets that do not belong to the company
    • Recently (less than 45 days) disclosed 0day vulnerabilities
    • Vulnerabilities affecting users of outdated browsers or platforms
    • Social engineering, phishing, physical, or other fraud activities
    • Publicly accessible login panels without proof of exploitation
    • Reports that state that software is out of date/vulnerable without a proof of concept
    • Reports that generated by scanners or any automated or active exploit tools
    • Vulnerabilities involving active content such as web browser add-ons
    • Most brute-forcing issues without clear impact
    • Denial of service (DoS/DDoS)
    • Theoretical issues
    • Moderately Sensitive Information Disclosure
    • Spam (sms, email, etc)
    • Missing HTTP security headers
    • Infrastructure vulnerabilities, including
    • Certificates/TLS/SSL-related issues
    • DNS issues (i.e. MX records, SPF records, DMARC records etc.)
    • Server configuration issues (i.e., open ports, TLS,etc.)
    • Open redirects
    • Session fixation
    • User account enumeration
    • Clickjacking/Tapjacking and issues only exploitable through clickjacking/tap jacking
    • Descriptive error messages (e.g. Stack Traces, application or server errors)
    • Self-XSS that cannot be used to exploit other users
    • Login & Logout CSRF
    • Weak Captcha/Captcha Bypass
    • Lack of Secure and HTTPOnly cookie flags
    • Username/email enumeration via Login/Forgot Password Page error messages
    • CSRF in forms that are available to anonymous users (e.g. the contact form)
    • OPTIONS/TRACE HTTP method enabled
    • Host header issues without proof-of-concept demonstrating the vulnerability
    • Content spoofing and text injection issues without showing an attack vector without being able to modify HTML/CSS
    • Content Spoofing without embedded links/HTML
    • Reflected File Download (RFD)
    • Mixed HTTP Content
    • HTTPS Mixed Content Scripts
    • No rate limit issues (without clear security impact)
    • Manipulation with Password Reset Token
    • MitM and local attacks

 

Handling Personally identifiable information (PII)

  • Personally, identifying information (PII) includes:
    • legal and/or full names
    • names or usernames combined with other identifiers like phone numbers or email addresses
    • KYC details
    • information about political or religious affiliations
    • information about race, ethnicity, sexual orientation, gender, or other identifying information that could be used for discriminatory purposes
  • Do not intentionally access others’ PII. If you suspect a service provides access to PII, limit queries to your own personal information.
  • Report the vulnerability immediately and do not attempt to access any other data. The OFZA Security team will assess the scope and impact of the PII exposure.
  • Limit the amount of data returned from services. For SQL injection, for example, limit the number of rows returned
  • You must delete all your local, stored, or cached copies of data containing PII as soon as possible. We may ask you to sign a certificate of deletion and confidentiality agreement regarding the exact information you accessed. This agreement will not affect your bounty reward.
  • We may ask you for the usernames and IP addresses used during your testing to assess the impact of the vulnerability

 

Reward Policy

We encourage responsible disclosure of security vulnerabilities. We will pay a reward in USD. Severity will be calculated by CVSS 3.0 Calculator.

Severity

Rewards

Critical

500 - 10k USD

High

250 - 500 USD

Medium

100 - 250 USD

Low

10 - 75 USD

Disclaimer

OFZA reserves the ultimate decision and will determine at its discretion whether a vulnerability is eligible for a reward and the amount of the award depending on severity. Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you.