Program Page Acknowledgements & Agreements
Read the following acknowledgments & agreements carefully to know what to expect during report triage
Awards/Payouts are granted for application based vulnerabilities within the main apps in scope.
Any non application related vulnerabilities reported are accepted as informational with no payout.
Make sure reports are complete - submissions missing vulnerability description, method of discovery, full HTTP request and response, potential impact and clear steps to reproduce will be rejected as invalid or accepted as informational with no payout. Remediation clarification - If a report is found to be a remediation bypass of a previously reported issue, the severity will be lower.
If Inspectiv finds that a vulnerability is systematic via multiple reports showcasing the same root cause, we reserve the right to mark those subsequent vulnerability reports as duplicates. Example: Reflected cross-site scripting is found on the parameter “email” for both ‘/user/new’ and ‘/user/update’. The root cause of this issue is improper input sanitization of the email parameter, therefore only one submission will be accepted between the two vulnerable endpoints.
All testing requires the usage of a HTTP header when sending requests. The format is: X-Inspectiv-Tester: {researcher-username} - Example Setup Intructions
Performing testing without following the required Rules of Engagement might render the security report ineligible for a bounty.
Please refrain from creating/deleting/changing mass records. In case you need to do so, please create your own records in the second organization if applicable.
Researchers can turn in their assigned credential at any time in order to receive another program’s credentials.
If you find a vulnerability accessing another account. Stop testing immediately and report vulnerability.
Do not publish vulnerabilities or share them outside of reporting through Inspectiv’s platform without Inspectiv’s consent.
Social engineering attacks against our employees or customers, including but not limited to phishing, vishing, or spear fishing attacks, are unacceptable.
Do not create a large number of records in your testing.
Do not leak, edit, or remove any information that is not on your own personal testing account.
Do not make any fraudulent monetary transactions and do not send high volume of traffic. If you’re testing for Rate Limiting, please do not exceed 10 requests/sec, and do not exceed 10 seconds.
Please be courteous to our Program Managers. They’re 100% here to help you.