د بګ انعام پروګرام

د تېروتنې راپور او د انعام پروګرام

موږ غواړو هغه تېروتنې ومومو چې تر اوسه مو پدې سایټ او زموږ په سیسټمونو کې نه دي موندلي، او د دې کار لپاره موږ ستاسو مرستې ته اړتیا لرو. موږ تاسو ته د هغه زیانونو لپاره انعام درکوو چې تاسو به زموږ په سیسټمونو کې ومومئ د لاندې مشخصو تېروتنو او مقرراتو په چوکاټ کې.

د بګ کچې او جایزې

  • P1 1250 ₺ - 3000 ₺
  • P2 500 ₺ - 1250 ₺
  • P3 150 ₺ - 500 ₺
  • P4 50 ₺ - 150 ₺
  • P5 0 ₺ - 50 ₺
  • P0 - 0 ₺ - که موږ تادیه ونکړو هم، موږ د امنیتي سایټونو او زموږ د ټولنیزو رسنیو پاڼې کې د تبصرو له لارې ستاسو ستاینه او سپارښتنه کوو.
سربیره پردې، موږ د ټولو هغو کسانو څخه چې تېروتنې یې راپور کړي مننه کوو چې پدې پاڼه کې (لاندې) یې خپروو.

قواعد او اړتیاوې

محرمیت:

محرمیت مهم دی. مخکې یا وروسته له دې چې تاسو موږ ته د زیانمننې راپور ورکړئ له چا سره یې مه شریکوئ. غیر محرم زیانمننې ته جایزه نه ورکول کیږي.

د سپارلو اړتیاوې:

  • هر امنیتي نیمګړتیا باید په جلا بریښنالیک کې راپور شي. که چیرې دمخه راپور شوې کومه نیمګړتیا شتون ولري، نو دا خبرتیاوې نه پروسس کیږي او ځواب نه ورکول کیږي.
  • د دې لپاره چې موږ زیان مننه وګورو، تاسو باید ټول هغه ګامونه چې تاسو د بګ په موندلو کې پلي کړي په ترتیب سره په تفصیل سره شریک کړئ.
  • د بریښنالیک لیږلو پرمهال، په دې سایټ کې خپل غړیتوب کارن نوم / بریښنالیک پته هم واستوئ. ستاسو لپاره د تادیې ترلاسه کولو لپاره غړیتوب او د هویت تصدیق اړین دی.
  • مشخص شوې نیمګړتیا باید د چا لخوا په فورم / پیغام / ټولنیز شبکه او نورو چاپیریال کې په ښکاره یا پټه توګه نه وي شریکه شوې.
  • هغه زیانمننې چې دمخه راپور شوي، په عامه یا خصوصي توګه د مختلفو خلکو سره شریکې شوي، نه ارزول کیږي.
  • که د کیګ د حل کولو په مرحله کې د مختلفو خلکو لخوا د هغې کارول وموندل شي، دا به انعام ورنکړل شي ځکه چې دا پدې مانا ده چې نور پوهیږي یا تاسو دا شریک کړی دی.
  • تاسو باید د هغه بګ توضیحي ویډیو او انځورونه چې راپور کیږي د بریښنالیک ضمیمې په توګه واستوئ. دا په هیڅ صورت باید د عکس یا ویډیو اپلوډ سایټونو ته اپلوډ نشي.
  • که زموږ ډله د بګ په موندلو پوه نشي، تاسو باید خپل د اړیکې معلومات واستوئ ترڅو دوی له تاسو څخه اضافي معلومات ترلاسه کړي.
  • که تاسو د راپور وروسته د انعام سربیره د نیمګړتیا بندولو لپاره زموږ په غوښتنه ملاتړ چمتو کولی شئ، چمتو شوی ملاتړ په جلا توګه چارج کیږي.
  • کله چې راپور شوې زیانمنتیا وتړل شي، ستاسو تادیه سمدلاسه ترسره کیږي. که دا موده له 60 ورځو څخه زیاته شي، ستاسو تادیه د زیانمنتیا بندیدو پرته د اعظمي 60 ورځو په پای کې ترسره کیږي.
  • زیان مننې باید زموږ له شرکت سره تړاو ولري. مسلې لکه د بریښنالیک درغلي، د ویب پاڼو سمول او داسې نور په دې چوکاټ کې نه ارزول کیږي.
  • هغه زیانمننې چې پکې کوم جرم نه وي شوی یا په غیرقانوني فعالیتونو کې نه وي کارول شوي ارزول کیږي.
  • زموږ د شرکت سرور پرته زموږ د پیرودونکو مدیریت لاندې خصوصي / مجازی سرور، هوسټ او ځانګړي سکریپټ زیانمنتیاوې د انعام له ساحې څخه بهر دي.
  • که د تېروتنې په کتنه کې د لاګ په تحلیل کې ولیدل شي چې سیسټم ته ننوتل شوي، کوم اقدام شوی یا شخصي معلومات اخیستل شوي، هیڅ انعام نه ورکول کیږي.
  • که تاسو برید کوئ، تاسو باید دمخه د معلوماتو په ورکولو سره اجازه ترلاسه کړئ. هغه زیانونه چې د اجازې پرته یا د اجازې ساعتونو څخه بهر ترسره شوي بریدونو څخه رامینځته کیږي انعام نه ورکول کیږي.
  • د زیانمننې په موندلو کې باید هیڅ خدمت یا پیرودونکي ته زیان ونه رسیږي. که چیرې زیان وموندل شي، دا د انعام فیس څخه د زیان کمولو له لارې ارزول کیږي.
  • بې نومه راپورونو ته جایزه نه ورکول کیږي، تاسو باید تادیه ترلاسه کولو لپاره په روښانه توګه ووایاست چې تاسو څوک یاست. ستاسو معلومات به زموږ سره محرم پاتې شي.
  • کله چې تاسو زیان مننه واستوئ، تاسو د راپور ټول فکري ملکیت زموږ شرکت ته لیږدئ او د راپور د کاپي حق څخه تېریږئ.
  • د انعام فیس په تادیه کې، ستاسو تادیه د شرکت لګښت له امله د 20٪ مالیې کسر په پلي کولو سره ترسره کیږي.
  • تادیه ستاسو بانکي حساب ته د IBAN یا PayPal له لارې کیږي. بټکوین یا بل د تادیې چینل نه کارول کیږي.
د سپارلو لپاره د بریښنالیک مسوده - نامکمل او بې تفصیله راپورونه به ونه ارزول شي او ځواب به ورنکړل شي.
موضوع: "د تېروتنې راپور: Px" E-Mail: سلام،, [سیسټم/سایټ/IP] ما ستاسو په سیسټم کې یوه تېروتنه وموندله، زه دا د انعام برنامې په چوکاټ کې راپور کوم. د بګ لومړیتوب: Px د بګ ډول: [د لاندې لیست څخه د بګ نوم] [مهرباني وکړئ د موندلو او تصدیق کولو لپاره دلته موږ ته تفصيلي معلومات راکړئ. تاسو باید هغه ګامونه تشریح کړئ چې موږ ورته اړتیا لرو ترڅو زیان منونکي وګورو، لکه څنګه چې تاسو ترسره کړي دي.] ضمیمې: [سربیره پردې، تاسو کولی شئ اسناد لکه ویډیو، عکس، pcap، txt، exe، pdf واستوئ، دا اسناد کیدای شي مخکې او وروسته انځورونه، مرحلې، سرلیک، غوښتنه، ځواب ډیټا وي] نوم او تخلص: د غړي کارن-نوم: د غړي بریښنالیک پته: د GSM شمیره: هیواد/ښار: د تادیې حساب: [IBAN یا PayPal حساب]په سایټ کې د مننې خپرولو لپاره مستعار نوم: [دا معلومات به زموږ د سایټ د بګ راپورونو په پاڼه کې خپاره شي، که تاسو نه غواړئ چې خپاره شي نو تش یې پریږدئ.] په ډېر درنښت.

د راپور ورکولو وړ ټول بګ ډولونه او کچې

Bugcrowd Vulnerability Rating Taxonomy (VRT 1.7)

P0Unsafe Cross-Origin Resource Sharing
Server Security Misconfiguration
P0Path Traversal
Server Security Misconfiguration
P0Sensitive Data Exposure
Server Security Misconfiguration -> Directory Listing Enabled
P0SSL Attack (BREACH, POODLE etc.)
Server Security Misconfiguration
P0Missing/Broken State Parameter
Server Security Misconfiguration -> OAuth Misconfiguration
P0Insecure Redirect URI
Server Security Misconfiguration -> OAuth Misconfiguration
P0Privilege Escalation
Broken Authentication and Session Management
P0Cross Site Script Inclusion (XSSI)
Sensitive Data Exposure
P0Insecure Direct Object References (IDOR)
Broken Access Control (BAC)
P0Exposed Sensitive Android Intent
Broken Access Control (BAC)
P0Exposed Sensitive iOS URL Scheme
Broken Access Control (BAC)
P0Authenticated Action
Cross-Site Request Forgery (CSRF) -> Action-Specific
P0Unauthenticated Action
Cross-Site Request Forgery (CSRF) -> Action-Specific
P0Cleartext Transmission of Sensitive Data
Insecure Data Transport
P1Using Default Credentials
Server Security Misconfiguration
P1Local
Server-Side Injection -> File Inclusion
P1Remote Code Execution (RCE)
Server-Side Injection
P1SQL Injection
Server-Side Injection
P1XML External Entity Injection (XXE)
Server-Side Injection
P1Authentication Bypass
Broken Authentication and Session Management
P1Password Disclosure
Sensitive Data Exposure -> Critically Sensitive Data
P1Private API Keys
Sensitive Data Exposure -> Critically Sensitive Data
P1Command Injection
Insecure OS/Firmware
P1Privileged User
Insecure OS/Firmware -> Hardcoded Password
P1Incorrect Usage
Broken Cryptography -> Cryptographic Flaw
P1PII Leakage
Automotive Security Misconfiguration -> Infotainment
P1Key Fob Cloning
Automotive Security Misconfiguration -> RF Hub
P2High Impact Subdomain Takeover
Server Security Misconfiguration -> Misconfigured DNS
P2Account Takeover
Server Security Misconfiguration -> OAuth Misconfiguration
P2Token Leakage via Host Header Poisoning
Sensitive Data Exposure -> Weak Password Reset Implementation
P2Non-Privileged User to Anyone
Cross-Site Scripting (XSS) -> Stored
P2Internal High Impact
Broken Access Control (BAC) -> Server-Side Request Forgery (SSRF)
P2Application-Wide
Cross-Site Request Forgery (CSRF)
P2Critical Impact and/or Easy Difficulty
Application-Level Denial-of-Service (DoS)
P2Non-Privileged User
Insecure OS/Firmware -> Hardcoded Password
P2Code Execution (CAN Bus Pivot)
Automotive Security Misconfiguration -> Infotainment
P2CAN Injection / Interaction
Automotive Security Misconfiguration -> RF Hub
P3Basic Subdomain Takeover
Server Security Misconfiguration -> Misconfigured DNS
P3No Spoofing Protection on Email Domain
Server Security Misconfiguration -> Mail Server Misconfiguration
P3Response Splitting (CRLF)
Server-Side Injection -> HTTP Response Manipulation
P3iframe Injection
Server-Side Injection -> Content Spoofing
P3Second Factor Authentication (2FA) Bypass
Broken Authentication and Session Management
P3HTTPS not Available or HTTP by Default
Broken Authentication and Session Management -> Weak Login Function
P3Remote Attack Vector
Broken Authentication and Session Management -> Session Fixation
P3Automatic User Enumeration
Sensitive Data Exposure -> EXIF Geolocation Data Not Stripped From Uploaded Images
P3Privileged User to Privilege Elevation
Cross-Site Scripting (XSS) -> Stored
P3CSRF/URL-Based
Cross-Site Scripting (XSS) -> Stored
P3Non-Self
Cross-Site Scripting (XSS) -> Reflected
P3Internal Scan and/or Medium Impact
Broken Access Control (BAC) -> Server-Side Request Forgery (SSRF)
P3High Impact and/or Medium Difficulty
Application-Level Denial-of-Service (DoS)
P3Default Folder Privilege Escalation
Client-Side Injection -> Binary Planting
P3Code Execution (No CAN Bus Pivot)
Automotive Security Misconfiguration -> Infotainment
P3Unauthorized Access to Services (API / Endpoints)
Automotive Security Misconfiguration -> Infotainment
P3Data Leakage / Pull Encryption Mechanism
Automotive Security Misconfiguration -> RF Hub
P4Zone Transfer
Server Security Misconfiguration -> Misconfigured DNS
P4Email Spoofing to Inbox due to Missing or Misconfigured DMARC on Email Domain
Server Security Misconfiguration -> Mail Server Misconfiguration
P4Excessively Privileged User / DBA
Server Security Misconfiguration -> Database Management System (DBMS) Misconfiguration
P4Delete Account
Server Security Misconfiguration -> Lack of Password Confirmation
P4Registration
Server Security Misconfiguration -> No Rate Limiting on Form
P4Login
Server Security Misconfiguration -> No Rate Limiting on Form
P4Email-Triggering
Server Security Misconfiguration -> No Rate Limiting on Form
P4SMS-Triggering
Server Security Misconfiguration -> No Rate Limiting on Form
P4Session Token
Server Security Misconfiguration -> Missing Secure or HTTPOnly Cookie Flag
P4Sensitive Click-Based Action
Server Security Misconfiguration -> Clickjacking
P4Implementation Vulnerability
Server Security Misconfiguration -> CAPTCHA
P4Cache-Control for a Sensitive Page
Server Security Misconfiguration -> Lack of Security Headers
P4Direct Server Access
Server Security Misconfiguration -> Web Application Firewall (WAF) Bypass
P4External Authentication Injection
Server-Side Injection -> Content Spoofing
P4Email HTML Injection
Server-Side Injection -> Content Spoofing
P4Cleartext Transmission of Session Token
Broken Authentication and Session Management
P4Other Plaintext Protocol with no Secure Alternative
Broken Authentication and Session Management -> Weak Login Function
P4LAN Only
Broken Authentication and Session Management -> Weak Login Function
P4HTTP and HTTPS Available
Broken Authentication and Session Management -> Weak Login Function
P4On Logout (Client and Server-Side)
Broken Authentication and Session Management -> Failure to Invalidate Session
P4On Password Reset and/or Change
Broken Authentication and Session Management -> Failure to Invalidate Session
P4Over HTTP
Broken Authentication and Session Management -> Weak Registration Implementation
P4Manual User Enumeration
Sensitive Data Exposure -> EXIF Geolocation Data Not Stripped From Uploaded Images
P4Detailed Server Configuration
Sensitive Data Exposure -> Visible Detailed Error/Debug Page
P4Untrusted 3rd Party
Sensitive Data Exposure -> Token Leakage via Referer
P4Over HTTP
Sensitive Data Exposure -> Token Leakage via Referer
P4User Facing
Sensitive Data Exposure -> Sensitive Token in URL
P4Password Reset Token Sent Over HTTP
Sensitive Data Exposure -> Weak Password Reset Implementation
P4Privileged User to No Privilege Elevation
Cross-Site Scripting (XSS) -> Stored
P4Flash-Based
Cross-Site Scripting (XSS)
P4IE11
Cross-Site Scripting (XSS) -> IE-Only
P4Referer
Cross-Site Scripting (XSS)
P4Universal (UXSS)
Cross-Site Scripting (XSS)
P4Data URI
Cross-Site Scripting (XSS) -> Off-Domain
P4External
Broken Access Control (BAC) -> Server-Side Request Forgery (SSRF)
P4Non-Brute Force
Broken Access Control (BAC) -> Username/Email Enumeration
P4GET-Based
Unvalidated Redirects and Forwards -> Open Redirect
P4No Password Policy
Insufficient Security Configurability
P4Token is Not Invalidated After Use
Insufficient Security Configurability -> Weak Password Reset Implementation
P42FA Secret Cannot be Rotated
Insufficient Security Configurability -> Weak 2FA Implementation
P42FA Secret Remains Obtainable After 2FA is Enabled
Insufficient Security Configurability -> Weak 2FA Implementation
P4Rosetta Flash
Using Components with Known Vulnerabilities
P4On External Storage
Insecure Data Storage -> Sensitive Application Data Stored Unencrypted
P4Plaintext
Insecure Data Storage -> Server-Side Credentials Storage
P4No Secure Integrity Check
Insecure Data Transport -> Executable Download
P4WiFi SSID+Password
Privacy Concerns -> Unnecessary Data Collection
P4On Sensitive Content
Mobile Security Misconfiguration -> Clipboard Enabled
P4Source Code Dump
Automotive Security Misconfiguration -> Infotainment
P4Denial of Service (DoS / Brick)
Automotive Security Misconfiguration -> Infotainment
P4Default Credentials
Automotive Security Misconfiguration -> Infotainment
P4Unauthorized Access / Turn On
Automotive Security Misconfiguration -> RF Hub
P4Injection (Disallowed Messages)
Automotive Security Misconfiguration -> CAN
P4Injection (DoS)
Automotive Security Misconfiguration -> CAN
P5Non-Sensitive Data Exposure
Server Security Misconfiguration -> Directory Listing Enabled
P5Same-Site Scripting
Server Security Misconfiguration
P5Missing Certification Authority Authorization (CAA) Record
Server Security Misconfiguration -> Misconfigured DNS
P5Email Spoofing to Spam Folder
Server Security Misconfiguration -> Mail Server Misconfiguration
P5Missing or Misconfigured SPF and/or DKIM
Server Security Misconfiguration -> Mail Server Misconfiguration
P5Email Spoofing on non-email domain
Server Security Misconfiguration -> Mail Server Misconfiguration
P5Change Email Address
Server Security Misconfiguration -> Lack of Password Confirmation
P5Change Password
Server Security Misconfiguration -> Lack of Password Confirmation
P5Manage 2FA
Server Security Misconfiguration -> Lack of Password Confirmation
P5No Antivirus
Server Security Misconfiguration -> Unsafe File Upload
P5No Size Limit
Server Security Misconfiguration -> Unsafe File Upload
P5File Extension Filter Bypass
Server Security Misconfiguration -> Unsafe File Upload
P5Cookie Scoped to Parent Domain
Server Security Misconfiguration
P5Non-Session Cookie
Server Security Misconfiguration -> Missing Secure or HTTPOnly Cookie Flag
P5Form Input
Server Security Misconfiguration -> Clickjacking
P5Non-Sensitive Action
Server Security Misconfiguration -> Clickjacking
P5Brute Force
Server Security Misconfiguration -> CAPTCHA
P5Missing
Server Security Misconfiguration -> CAPTCHA
P5To Internet
Server Security Misconfiguration -> Exposed Admin Portal
P5Missing DNSSEC
Server Security Misconfiguration
P5Fingerprinting/Banner Disclosure
Server Security Misconfiguration
P5Brute Force
Server Security Misconfiguration -> Username/Email Enumeration
P5OPTIONS
Server Security Misconfiguration -> Potentially Unsafe HTTP Method Enabled
P5TRACE
Server Security Misconfiguration -> Potentially Unsafe HTTP Method Enabled
P5Lack of Forward Secrecy
Server Security Misconfiguration -> Insecure SSL
P5Insecure Cipher Suite
Server Security Misconfiguration -> Insecure SSL
P5Certificate Error
Server Security Misconfiguration -> Insecure SSL
P5Reflected File Download (RFD)
Server Security Misconfiguration
P5X-Frame-Options
Server Security Misconfiguration -> Lack of Security Headers
P5Cache-Control for a Non-Sensitive Page
Server Security Misconfiguration -> Lack of Security Headers
P5X-XSS-Protection
Server Security Misconfiguration -> Lack of Security Headers
P5Strict-Transport-Security
Server Security Misconfiguration -> Lack of Security Headers
P5X-Content-Type-Options
Server Security Misconfiguration -> Lack of Security Headers
P5Content-Security-Policy
Server Security Misconfiguration -> Lack of Security Headers
P5Public-Key-Pins
Server Security Misconfiguration -> Lack of Security Headers
P5X-Content-Security-Policy
Server Security Misconfiguration -> Lack of Security Headers
P5X-Webkit-CSP
Server Security Misconfiguration -> Lack of Security Headers
P5Content-Security-Policy-Report-Only
Server Security Misconfiguration -> Lack of Security Headers
P5Bitsquatting
Server Security Misconfiguration
P5Social Media Sharing Buttons
Server-Side Injection -> Parameter Pollution
P5Flash Based External Authentication Injection
Server-Side Injection -> Content Spoofing
P5Email Hyperlink Injection Based on Email Provider
Server-Side Injection -> Content Spoofing
P5Text Injection
Server-Side Injection -> Content Spoofing
P5Homograph/IDN-Based
Server-Side Injection -> Content Spoofing
P5Right-to-Left Override (RTLO)
Server-Side Injection -> Content Spoofing
P5Not Operational or Intended Public Access
Broken Authentication and Session Management -> Weak Login Function
P5Local Attack Vector
Broken Authentication and Session Management -> Session Fixation
P5On Logout (Server-Side Only)
Broken Authentication and Session Management -> Failure to Invalidate Session
P5Concurrent Sessions On Logout
Broken Authentication and Session Management -> Failure to Invalidate Session
P5On Email Change
Broken Authentication and Session Management -> Failure to Invalidate Session
P5Long Timeout
Broken Authentication and Session Management -> Failure to Invalidate Session
P5Concurrent Logins
Broken Authentication and Session Management
P5Full Path Disclosure
Sensitive Data Exposure -> Visible Detailed Error/Debug Page
P5Descriptive Stack Trace
Sensitive Data Exposure -> Visible Detailed Error/Debug Page
P5Disclosure of Known Public Information
Sensitive Data Exposure
P5Trusted 3rd Party
Sensitive Data Exposure -> Token Leakage via Referer
P5In the Background
Sensitive Data Exposure -> Sensitive Token in URL
P5On Password Reset
Sensitive Data Exposure -> Sensitive Token in URL
P5Non-Sensitive Token in URL
Sensitive Data Exposure
P5Mixed Content (HTTPS Sourcing HTTP)
Sensitive Data Exposure
P5OAuth Secret
Sensitive Data Exposure -> Sensitive Data Hardcoded
P5File Paths
Sensitive Data Exposure -> Sensitive Data Hardcoded
P5Internal IP Disclosure
Sensitive Data Exposure
P5JSON Hijacking
Sensitive Data Exposure
P5Self
Cross-Site Scripting (XSS) -> Stored
P5Self
Cross-Site Scripting (XSS) -> Reflected
P5Cookie-Based
Cross-Site Scripting (XSS)
P5XSS Filter Disabled
Cross-Site Scripting (XSS) -> IE-Only
P5Older Version (< IE11)
Cross-Site Scripting (XSS) -> IE-Only
P5TRACE Method
Cross-Site Scripting (XSS)
P5DNS Query Only
Broken Access Control (BAC) -> Server-Side Request Forgery (SSRF)
P5Logout
Cross-Site Request Forgery (CSRF) -> Action-Specific
P5CSRF Token Not Unique Per Request
Cross-Site Request Forgery (CSRF)
P5Malformed Android Intents
Application-Level Denial-of-Service (DoS) -> App Crash
P5Malformed iOS URL Schemes
Application-Level Denial-of-Service (DoS) -> App Crash
P5POST-Based
Unvalidated Redirects and Forwards -> Open Redirect
P5Header-Based
Unvalidated Redirects and Forwards -> Open Redirect
P5Flash-Based
Unvalidated Redirects and Forwards -> Open Redirect
P5Tabnabbing
Unvalidated Redirects and Forwards
P5Lack of Security Speed Bump Page
Unvalidated Redirects and Forwards
P5Plaintext Password Field
External Behavior -> Browser Feature
P5Save Password
External Behavior -> Browser Feature
P5Autocomplete Enabled
External Behavior -> Browser Feature
P5Autocorrect Enabled
External Behavior -> Browser Feature
P5Aggressive Offline Caching
External Behavior -> Browser Feature
P5CSV Injection
External Behavior
P5Crowdsourcing
External Behavior -> Captcha Bypass
P5Shared Links
External Behavior -> System Clipboard Leak
P5User Password Persisted in Memory
External Behavior
P5Weak Password Policy
Insufficient Security Configurability
P5Token is Not Invalidated After Email Change
Insufficient Security Configurability -> Weak Password Reset Implementation
P5Token is Not Invalidated After Password Change
Insufficient Security Configurability -> Weak Password Reset Implementation
P5Token Has Long Timed Expiry
Insufficient Security Configurability -> Weak Password Reset Implementation
P5Token is Not Invalidated After New Token is Requested
Insufficient Security Configurability -> Weak Password Reset Implementation
P5Token is Not Invalidated After Login
Insufficient Security Configurability -> Weak Password Reset Implementation
P5Lack of Verification Email
Insufficient Security Configurability
P5Lack of Notification Email
Insufficient Security Configurability
P5Allows Disposable Email Addresses
Insufficient Security Configurability -> Weak Registration Implementation
P5Missing Failsafe
Insufficient Security Configurability -> Weak 2FA Implementation
P5Outdated Software Version
Using Components with Known Vulnerabilities
P5OCR (Optical Character Recognition)
Using Components with Known Vulnerabilities -> Captcha Bypass
P5On Internal Storage
Insecure Data Storage -> Sensitive Application Data Stored Unencrypted
P5Non-Sensitive Application Data Stored Unencrypted
Insecure Data Storage
P5Screen Caching Enabled
Insecure Data Storage
P5Lack of Exploit Mitigations
Lack of Binary Hardening
P5Lack of Jailbreak Detection
Lack of Binary Hardening
P5Lack of Obfuscation
Lack of Binary Hardening
P5Runtime Instrumentation-Based
Lack of Binary Hardening
P5Secure Integrity Check
Insecure Data Transport -> Executable Download
P5Telnet Enabled
Network Security Misconfiguration
P5Absent
Mobile Security Misconfiguration -> SSL Certificate Pinning
P5Defeatable
Mobile Security Misconfiguration -> SSL Certificate Pinning
P5Tapjacking
Mobile Security Misconfiguration
P5On Non-Sensitive Content
Mobile Security Misconfiguration -> Clipboard Enabled
P5Non-Default Folder Privilege Escalation
Client-Side Injection -> Binary Planting
P5No Privilege Escalation
Client-Side Injection -> Binary Planting
P5Roll Jam
Automotive Security Misconfiguration -> RF Hub
P5Replay
Automotive Security Misconfiguration -> RF Hub
P5Relay
Automotive Security Misconfiguration -> RF Hub

هغه امنیتي کارپوهان چې زموږ ملاتړ یې کړی

Hall of Fame / Onur Tablosu

  • Deniz Bektaş د P1 کچې د کوربه پینل RCE زیان مننې راپور لپاره مننه.
  • Eray TOPUZ د P1 کچې د کوربه پینل sql انجیکشن راپور لپاره مننه.
  • Salih Dumlu د P3 او P5 کچې راپورونو لپاره مننه.
  • Furkan Ali SOYSAL د P3 کچې د XSS خبرتیا لپاره مننه.
  • Deniz Bektaş د P3 کچې د XSS خبرتیا لپاره مننه.
  • DosH@X زموږ د امنیتي کوربه سیسټمونو کې د tar.gz ډیکمپریس سمبولیک لینک زیان مننې راپور لپاره مننه.
  • Buğra Eskici د P3 کچې د XSS خبرتیا لپاره مننه.
  • nitrozeus د P3 کچې د XSS خبرتیا لپاره مننه.
  • mefkan د P3 کچې د XSS خبرتیا لپاره مننه.
  • Akıner Kısa د 2x P3 کچې د XSS خبرتیا لپاره مننه.
  • phlm0x د P2 کچې امنیتي پرمختګ د خبرتیا لپاره مننه.
  • Mustafa Kemal Can - muskecan د P5 کچې د ناستې امنیت ښه کولو لپاره مننه.

راځئ چې تاسو Yöncü ته واستوو!

د نورو چمتو کونکو څخه زموږ شرکت ته ستاسو د خدماتو ګړندي لیږد لپاره له موږ سره اړیکه ونیسئ؛ موږ ۲۴/۷ ګړندی ملاتړ وړاندې کوو.

د لیږد فورمه

د معاملې تایید

ایا تاسو ډاډه یاست چې دا معامله ترسره کول غواړئ؟