0% found this document useful (0 votes)
30 views11 pages

Test 11 Pages

Uploaded by

pierre.payet
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
30 views11 pages

Test 11 Pages

Uploaded by

pierre.payet
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 11

Yes We Hack - Bug Bounty

Program

This program will be published on the Yes We Hack platform : https://yeswehack.com/

What we'll reward :

This program is targeted at our web platform only.


Rewards will be valued at our discretion according to our own severity evaluation, we
especially value vulnerabilities that could be exploited to:

 perform a significant action on behalf of another user


 gain free access to a normally paid / restricted service
 perform an unauthorised operation without an upgraded account
 access to users personal data
Reports must include a detailed realistic attack scenario. We ask you to explain as clearly as
you can what an attacker can actually do using the vulnerability you've discovered. We're
not interested in customers injecting javascript alerts but a scenario in which a stored XSS
allows an attacker to harvest sensitive data from our customers will be rewarded.

What we won't reward :

We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We'll only reward the first person to report a vulnerability, if you come next (unless with a
different exploitation proof of concept) you won't be rewarded.

Responsibility charter :

By participating to this program, you agree:

 not to target a real customer, whether it be physically or virtually and to only use
your own test accounts to reach your goals
 not to impact other customers with your testing
 not to disclose any vulnerability you may discover until we fix it
 not to alter data except for what you input yourself
 not to disclose data you may have extracted from our system
 to only extract the bare minimum of data needed to prove your point
 not to edit our system (neither code nor infrastructure)
 not to leave a backdoor after you've proved your point
 not to put the system out of service (using DDoS or exploiting a vulnerability)
 not to put the system under heavy load: refrain from using scanners or don't go
beyond 2 requests per second
Any failure to comply with this charter could be sanctioned with legal actions.

Our commitments :

 We'll review your reports as soon as possible and will keep you updated throughout
the whole process
 We'll do our best to fix reported vulnerabilities in a timely manner
 Should we decline a report, we'll explain why
 You'll be free to publicly disclose your discovery as soon as we tell you we fixed it (or
don't intend to fix it)

Reward :

 Low : 50€
 Medium : 200€
 High : 350€
 Critical : 500€
Qualifying vulnerabilities :

 Remote code execution


 Code injections
 Authentication flaws
 Authorisation flaws / privilege escalation
 Cross-Site Request Forgery with real security impact
 Cross-Site Scripting
 Clickjacking
 Unciphered HTTP access and mixed content
 Sensitive data exposure
 Sensitive Information Exposure Through insecure data storage

Non-qualifying vulnerabilities :
 Already known issues
 Anything we can't reproduce
 Hypothetical flaw or best practices without exploitable POC and concrete attack
scenario
 Untechnical attacks (phishing, social engineered or physical assault)
 Issues that require physical access to a victim's device
 Denial of service attacks
 Any third party provider's software vulnerabilities
 Vulnerable version of libraries (for example ‘jquery’) without demonstrable attack
vector
 Logout and other instances of low-severity Cross-Site Request Forgery
 Technical information disclosure
 Missing security-related HTTP headers which do not lead directly to a vulnerability
 Self XSS unless stored
 Password and account recovery policies, such as reset link expiration or password
complexity
 Lack of code obfuscation
 Crashing your own application
 SSL cypher suites
 SSL Pinning
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.
We don't plan to pay rewards for finding bugs not directly related to security (500 errors,
incorrect display, usability flaws) but feel free to tell us anyway if you find any :-)
We already know about a few vulnerabilities we don't intend to fix (listed in unqualifying
vulnerabilities). Reporting them won't be rewarded unless they give way to another actual
vulnerability.
It's also possible that we've already identified but not yet fixed an issue, you won't be
rewarded either in this case.

You might also like