Yes We Hack - Bug Bounty
Program
This program will be published on the Yes We Hack platform : https://yeswehack.com/
What we'll reward :
This program is targeted at our web platform only.
Rewards will be valued at our discretion according to our own severity evaluation, we
especially value vulnerabilities that could be exploited to:
perform a significant action on behalf of another user
gain free access to a normally paid / restricted service
perform an unauthorised operation without an upgraded account
access to users personal data
Reports must include a detailed realistic attack scenario. We ask you to explain as clearly as
you can what an attacker can actually do using the vulnerability you've discovered. We're
not interested in customers injecting javascript alerts but a scenario in which a stored XSS
allows an attacker to harvest sensitive data from our customers will be rewarded.
What we won't reward :
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We'll only reward the first person to report a vulnerability, if you come next (unless with a
different exploitation proof of concept) you won't be rewarded.
Responsibility charter :
By participating to this program, you agree:
not to target a real customer, whether it be physically or virtually and to only use
your own test accounts to reach your goals
not to impact other customers with your testing
not to disclose any vulnerability you may discover until we fix it
not to alter data except for what you input yourself
not to disclose data you may have extracted from our system
to only extract the bare minimum of data needed to prove your point
not to edit our system (neither code nor infrastructure)
not to leave a backdoor after you've proved your point
not to put the system out of service (using DDoS or exploiting a vulnerability)
not to put the system under heavy load: refrain from using scanners or don't go
beyond 2 requests per second
Any failure to comply with this charter could be sanctioned with legal actions.
Our commitments :
We'll review your reports as soon as possible and will keep you updated throughout
the whole process
We'll do our best to fix reported vulnerabilities in a timely manner
Should we decline a report, we'll explain why
You'll be free to publicly disclose your discovery as soon as we tell you we fixed it (or
don't intend to fix it)
Reward :
Low : 50€
Medium : 200€
High : 350€
Critical : 500€
Qualifying vulnerabilities :
Remote code execution
Code injections
Authentication flaws
Authorisation flaws / privilege escalation
Cross-Site Request Forgery with real security impact
Cross-Site Scripting
Clickjacking
Unciphered HTTP access and mixed content
Sensitive data exposure
Sensitive Information Exposure Through insecure data storage
Non-qualifying vulnerabilities :
Already known issues
Anything we can't reproduce
Hypothetical flaw or best practices without exploitable POC and concrete attack
scenario
Untechnical attacks (phishing, social engineered or physical assault)
Issues that require physical access to a victim's device
Denial of service attacks
Any third party provider's software vulnerabilities
Vulnerable version of libraries (for example ‘jquery’) without demonstrable attack
vector
Logout and other instances of low-severity Cross-Site Request Forgery
Technical information disclosure
Missing security-related HTTP headers which do not lead directly to a vulnerability
Self XSS unless stored
Password and account recovery policies, such as reset link expiration or password
complexity
Lack of code obfuscation
Crashing your own application
SSL cypher suites
SSL Pinning
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.