The OFZA team acknowledges the critical role that security researchers play in safeguarding our community. We strongly encourage the responsible disclosure of security vulnerabilities through our Bug Bounty Program, as outlined on this page.
Program Rule
Check the list of domains that are in scope for the Bug Bounty program.
Make a good faith effort to avoid privacy violations, destruction of data interruption, or degradation of our businesses, including Denial of Services attacks.
Not exploit the vulnerability in any way, including through making it public or by obtaining a profit (other than a reward under this Program).
Please do not publicly disclose any vulnerabilities without our consent. We will not approve Public Disclosure requests until the vulnerability has been resolved.
Do not attempt non-technical attacks such as social engineering, phishing, or physical attacks against our employees, users, or infrastructure.
Do not use scanners or automated tools to find vulnerabilities. They are noisy and we may ban your IP address.
Submit only one vulnerability per submission unless you need to chain vulnerabilities to provide impact regarding any of the vulnerabilities.
In case we receive duplicate reports of a specific vulnerability, only the first report is eligible for a reward.
By submitting a bug, you agree to be bound by the rules.
Vulnerabilities found in out of scope resources are unlikely to be rewarded unless they present a serious business risk (at our sole discretion). In general, the following vulnerabilities do not correspond to the severity threshold:
Vulnerabilities in third-party applications
Assets that do not belong to the company
Recently (less than 45 days) disclosed 0day vulnerabilities
Vulnerabilities affecting users of outdated browsers or platforms
Social engineering, phishing, physical, or other fraud activities
Publicly accessible login panels without proof of exploitation
Reports that state that software is out of date/vulnerable without a proof of concept
Reports that generated by scanners or any automated or active exploit tools
Vulnerabilities involving active content such as web browser add-ons
Most brute-forcing issues without clear impact
Denial of service (DoS/DDoS)
Theoretical issues
Moderately Sensitive Information Disclosure
Spam (sms, email, etc)
Missing HTTP security headers
Infrastructure vulnerabilities, including
Certificates/TLS/SSL-related issues
DNS issues (i.e. MX records, SPF records, DMARC records etc.)
Server configuration issues (i.e., open ports, TLS,etc.)
Open redirects
Session fixation
User account enumeration
Clickjacking/Tapjacking and issues only exploitable through clickjacking/tap jacking
Descriptive error messages (e.g. Stack Traces, application or server errors)
Self-XSS that cannot be used to exploit other users
Login & Logout CSRF
Weak Captcha/Captcha Bypass
Lack of Secure and HTTPOnly cookie flags
Username/email enumeration via Login/Forgot Password Page error messages
CSRF in forms that are available to anonymous users (e.g. the contact form)
OPTIONS/TRACE HTTP method enabled
Host header issues without proof-of-concept demonstrating the vulnerability
Content spoofing and text injection issues without showing an attack vector without being able to modify HTML/CSS
Content Spoofing without embedded links/HTML
Reflected File Download (RFD)
Mixed HTTP Content
HTTPS Mixed Content Scripts
No rate limit issues (without clear security impact)
Manipulation with Password Reset Token
MitM and local attacks
Handling Personally identifiable information (PII)
Personally, identifying information (PII) includes:
legal and/or full names
names or usernames combined with other identifiers like phone numbers or email addresses
KYC details
information about political or religious affiliations
information about race, ethnicity, sexual orientation, gender, or other identifying information that could be used for discriminatory purposes
Do not intentionally access others’ PII. If you suspect a service provides access to PII, limit queries to your own personal information.
Report the vulnerability immediately and do not attempt to access any other data. The OFZA Security team will assess the scope and impact of the PII exposure.
Limit the amount of data returned from services. For SQL injection, for example, limit the number of rows returned
You must delete all your local, stored, or cached copies of data containing PII as soon as possible. We may ask you to sign a certificate of deletion and confidentiality agreement regarding the exact information you accessed. This agreement will not affect your bounty reward.
We may ask you for the usernames and IP addresses used during your testing to assess the impact of the vulnerability
Reward Policy
We encourage responsible disclosure of security vulnerabilities. We will pay a reward in USD. Severity will be calculated by CVSS 3.0 Calculator.
Severity
Rewards
Critical
500 - 10k USD
High
250 - 500 USD
Medium
100 - 250 USD
Low
10 - 75 USD
Disclaimer
OFZA reserves the ultimate decision and will determine at its discretion whether a vulnerability is eligible for a reward and the amount of the award depending on severity. Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you.