BUG REPORT AND REWARD PROGRAM
We want to detect bugs that we have not yet found in this site and our systems, and we need your help to do this. We reward you within the scope of the bugs and rules specified below for the vulnerabilities you will find in our systems.
Bug Levels and Rewards
- P1 1250 ₺ - 3000 ₺
- P2 500 ₺ - 1250 ₺
- P3 150 ₺ - 500 ₺
- P4 50 ₺ - 150 ₺
- P5 0 ₺ - 50 ₺
- P0 - 0 ₺ - Even if we cannot pay, we praise and recommend you by commenting on security sites and our social media page.
RULES & REQUIREMENTS
PRIVACY:
Privacy is important. Do not share the vulnerability with anyone before or after you report it to us. Unconfidential vulnerabilities are not rewarded.
Submission Requirements:
- Each vulnerability must be reported in a separate email. If there is a previously reported vulnerability, these notifications are not processed and are not answered.
- In order for us to see the vulnerability, you must convey all the steps you applied in the bug detection in detail in order.
- When sending an e-mail, also send your membership username / e-mail address on this site. Membership and identity verification are required for you to receive payment.
- The specified bug must not have been shared openly or secretly by anyone in a forum / message / social network etc. environment.
- Vulnerabilities reported previously, publicly or privately shared with different people are not evaluated.
- If its use by different people is detected during the bug closing phase, it will not be rewarded as it means others know or you shared it.
- You must send the bug description video and pictures to be reported as an attachment to the e-mail. They absolutely should not be uploaded to picture or video upload sites.
- If our team does not understand the bug detection, you must forward your contact information for them to get additional information from you.
- If you can support upon our request to close the bug in addition to the reward after the report, the support provided is charged separately.
- When the reported vulnerability is closed, your payment is made immediately. If this period exceeds 60 days, your payment is made at the end of maximum 60 days without the vulnerability being closed.
- Vulnerabilities must be related to our company. Issues such as e-mail fraud, editing of web sites, etc. are not evaluated within this scope.
- Vulnerabilities where no crime has been committed or not used in illegal activities are evaluated.
- Private / virtual server, host and special script vulnerabilities under the management of our customers other than our company server are out of the scope of the reward.
- If it is seen in the log analysis in the bug review that the system was entered, an action was taken or personal information was taken, no reward is provided.
- If you are going to attack, you must get permission by giving information in advance. Vulnerabilities arising from attacks carried out without permission or outside permission hours are not rewarded.
- No service or customer should be harmed in vulnerability detections. If a damage is detected, it is evaluated by deducting the damage from the reward fee.
- Anonymous reports are not rewarded, you must clearly state who you are to receive payment. Your information remains confidential with us.
- When you send a vulnerability, you transfer all intellectual property of the report to our company and waive the copyright of the report.
- In the reward fee payment, your payment is made by applying a 20% tax deduction due to company expense.
- Payment is made to your bank account via IBAN or via PayPal. Bitcoin or a different payment channel is not used.
Email Draft for Submission - Incomplete and un-detailed reports will not be evaluated and answered.
ALL REPORTABLE BUG TYPES AND LEVELS
Bugcrowd Vulnerability Rating Taxonomy (VRT 1.7)
SECURITY EXPERTS WHO SUPPORTED US
Hall of Fame / Onur Tablosu
-
Deniz Bektaş Thank you for the P1 level host panel RCE vulnerability report.
-
Eray TOPUZ Thank you for the P1 level host panel sql injection report.
-
Salih Dumlu Thank you for the P3 and P5 level reports.
-
Furkan Ali SOYSAL Thank you for the P3 level XSS notification.
-
Deniz Bektaş Thank you for the P3 level XSS notification.
-
DosH@X Thank you for the tar.gz decompress sym link vulnerability report in our security host systems.
-
Buğra Eskici Thank you for the P3 level XSS notification.
-
nitrozeus Thank you for the P3 level XSS notification.
-
mefkan Thank you for the P3 level XSS notification.
-
Akıner Kısa Thank you for 2x P3 level XSS notification.
-
phlm0x Thank you for the P2 level security improvement notification.
-
Mustafa Kemal Can - muskecan Thank you for the P5 level session security improvement.