Geizhals Code Bounty
Geizhals » Forum » Geizhals » Geizhals Bug Bounty (48 Beiträge, 2329 Mal gelesen) Top-100 | Fresh-100
Du bist nicht angemeldet. [ Login/Registrieren ]
Geizhals Code Bounty
11.12.2013, 19:34:48


Geizhals Bug Bounty Program
===========================================
DRAFT, valid from 21.12.2013 as published at that date.


General terms:


  • applies to websites using the domains: geizhals.at, geizhals.de, geizhals.eu, compare.eu, skinflint.co.uk, cenowarka.pl
  • in some cases, multiple reports for seemingly different websites might refer to the exact same problem / piece of code, because e.g. skinflint.co.uk uses the same code as geizhals.at etc. - here we will consider these multiple reports as one at our discretion.
  • we may offer to pay bounties in the form of Amazon vouchers (we will let you choose from Amazon.de, Amazon.co.uk and possibly others if we can pay them without tax issues)
  • we will publish information about submissions with as much detail as we choose to
  • first come, first serve - bounties are paid to first submitter only and only once per type of vulnerability (not for different ways of exploiting the same or for each account compromised etc.)
  • damages caused unnecessarily will be subtracted from bounties (we'll be fair). If too much avoidable damage was caused, we may refuse to pay bounties (please don't do it, this bug bounty program does not exist in order to invite people to cause damage to us)
  • known vulnerabilities we are trying to fix and published by us already, are excluded
  • if multiple cases below apply, the highest is paid, except for vulnerable 3rd party code (i.e. Debian packages), where we pay only the bounty for that category (the best matching)
  • all submissions must be sent to bugbounty@geizhals.at and readable with MUAs without HTML support
  • exploit details must not be published elsewhere before we've had reasonable time to fix the problem
  • we may update the terms / bounties however we wish at any time without prior notice, however for submitted bugs sent before new terms are announced, the old terms will apply
  • we must be able to reproduce reported bugs without an unusual/exotic platform/configuration
  • we will try to be as fair and objective as possible, however if we cannot afford some bounties or  if we made stupid mistakes in the terms published that allow exploitation in an unintended way, we  reserve the right to refuse bounties. Please be fair and reasonable too!


SEVERITY           BOUNTY            EXTRA TERMS
-------------------------------------------------------------------------
XSS                €100              

CSRF               €100               if user data can be manipulated through 3rd party websites

SQL Injection   €200

Capturing a user
account            €150              Brute-forcing, phishing or MITM are not applicable. Using XSS:
                                     XSS bounty above will apply.

Severe DoS
opportunity        €200              When a particular request/URL causes effective DoS with
                                     1 hit per 60 seconds (yes we know about forum search and
                                     best merchant combination calculations, they are slow...)

Remote code
execution/login    €500

Remote code exec.
as root            €1000

Any of the above
when caused by 3rd
party bug with fix
available for 48h
or longer          €200

Any of the above
when caused by 3rd
party bug with fix
available for <48h €0 (because we'll hopefully fix it automatically)

Any of the above
when caused by 3rd
party bug with NO
fix available yet  CONTACT DEBIAN/appropriate authorities urgently!



Google-Suchergebnisse, nur mit Privatsphäre? startpage.com!


Once you allow the government to start breaking the law, no matter how seemingly justifiable the reason, you relinquish the contract between you and the government which establishes that the government works for and obeys you, the citizen—the employer—the master. And once the government starts operating outside the law, answerable to no one but itself, there’s no way to rein it back in, short of revolution.
-- John W. Whitehead

Zwangsbejagung Ade!

19.12.2013, 07:43 Uhr - Editiert von mjy@geizhals.at, alte Version: hier
[ Dieser Beitrag wurde inzwischen editiert. Die aktuelle Version befindet sich hier. ]
Antworten PM Alle Chronologisch
 
Melden nicht möglich
  Geizhals Code Bounty
 (mjy@geizhals.at am 11.12.2013, 19:34:48)
.  Known/Disclosed Bugs  (mjy@geizhals.at am 11.12.2013, 19:52:59)
.  Re: Geizhals Code Bounty
 (AVS_reloaded am 11.12.2013, 22:26:16)
.  Re: Geizhals Code Bounty
 (bono_d70 am 12.12.2013, 10:00:07)
..  Re(2): Geizhals Code Bounty  (mjy@geizhals.at am 12.12.2013, 10:05:09)
...  Re(3): Geizhals Code Bounty  (hellbringer am 12.12.2013, 10:11:11)
....  Re(4): Geizhals Code Bounty
 (bono_d70 am 12.12.2013, 10:13:44)
...  Re(3): Geizhals Code Bounty  (bono_d70 am 12.12.2013, 10:13:14)
. Vom Autor zurückgezogen oder Autor hat seine Registrierung nicht bestätigt  (*patrick star* am 06.01.2014, 19:18:33)
.  Re: Geizhals Code Bounty  (zeddicus am 14.08.2014, 20:03:20)
..  Re(2): Geizhals Code Bounty  (TuxTux am 14.08.2014, 20:07:10)
...  Re(3): Geizhals Code Bounty
 (mjy@geizhals.at am 15.08.2014, 01:35:41)
....  Re(4): Geizhals Code Bounty  (MotzTussy am 15.08.2014, 10:16:00)
.....  Re(5): Geizhals Code Bounty  (mjy@geizhals.at am 15.08.2014, 10:36:31)
.  Re: Geizhals Code Bounty  (x264 am 03.08.2015, 09:36:48)
..  Re(2): Geizhals Code Bounty
 (Instar am 03.08.2015, 11:29:34)
...  Re(3): Geizhals Code Bounty
 (x264 am 03.08.2015, 11:34:44)
....  Re(4): Geizhals Code Bounty  (Instar am 03.08.2015, 11:37:09)
...  Re(3): Geizhals Code Bounty
 (m3xx am 04.08.2015, 16:46:21)
....  Re(4): Geizhals Code Bounty  (Instar am 05.08.2015, 07:54:59)
...  Re(3): Geizhals Code Bounty  (*patrick star* am 04.08.2015, 19:31:51)
....  Re(4): Geizhals Code Bounty  (Instar am 05.08.2015, 07:52:59)
 

Dieses Forum ist eine frei zugängliche Diskussionsplattform.
Der Betreiber übernimmt keine Verantwortung für den Inhalt der Beiträge und behält sich das Recht vor, Beiträge mit rechtswidrigem oder anstößigem Inhalt zu löschen.
Datenschutzerklärung