52235 policies in database
Link to program      
2021-01-02
backmarket.de logo
Thank
Gift
HOF
Reward

backmarket.de

A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512


# Thinking you found a security vulnerability? Let's talk and take a responsible disclosure path together.
# In a nutshell, we are interested in real vulnerabilities that could substantially affect the confidentiality or
# integrity of Back Market's Customers and/or Merchants data, not output of automated scanners.

# Following vulnerabilities are examples of vulnerabilities that are *out-of-scope*:
# * reports from automated tools or scans
# * lack of, or insufficient, rate limiting on an endpoint
# * outdated software without any noteworthy vulnerability
# * missing security headers which do not lead directly to a vulnerability
# * lack of CSRF tokens which do not lead directly to a vulnerability
# * missing security best practice which do not lead directly to a vulnerability

# When submitting a vulnerability report, please always ensure to provide at least *precise* and detailed steps to
# reproduce all described attack scenarios. Additionally, screenshots, samples, scripts, ... are all helpful.
# Without precise information, we won't be able to qualify the submission as an exploitable security vulnerability.
# Also, please be realistic: bugs requiring exceedingly unlikely user interaction such as entering manually an
# attack payload, going through forged third party phishing pages, etc. may realistically not meet the bar.
# Due to large amount of emails, we might not be able to respond to all reports for out-of-scope vulnerabilities.
Contact: mailto:security@backmarket.com

# Sensitive information require adequate protection, and cleartext in email body does not serve that objective.
# Therefore, please always encrypt your vulnerability report and provide it as an email attachment.
Encryption: https://www.backmarket.com/.well-known/security-pubkey.txt
Encryption: https://pgp.key-server.io/download/0x5EDD605BB8F4C0DD
Encryption: openpgp4fpr:2cebfa0bd82d37009ab2add25edd605bb8f4c0dd

# Back Market is continually looking for new talents, this might be a good opportunity to reach out!
Hiring: https://jobs.backmarket.com/

# You know how it works, right? Past the expiration date, consuming info from this file is at your own risk.
Expires: Mon, 20 Dec 2021 00:00:00 -0800

-----BEGIN PGP SIGNATURE-----

iQJMBAEBCgA2FiEELOv6C9gtNwCasq3SXt1gW7j0wN0FAmDR6gMYHHNlY3VyaXR5
QGJhY2ttYXJrZXQuY29tAAoJEF7dYFu49MDdj2QP/0ZyZ/4PEK3Dde94lLv4862G
BzEkJjKFJr6UfP7rRmZelpyaX1kbkRyKIQMUBDNXUXHfv/ZLN1pRxbnKCKvBJsUE
tBNqxXKF0ajtV9Z7XTOknLAWBSLLe6Vo7tXekAVqXsi4U9QEAu37rhe4QyT5YnD+
FnkZjVQpGGuYR6cFWrbirTZr2zRRrPFzboIjOrI8YPhRcIZ5B4f7aiTdGzL5suly
eoUqu7uWslFQbZld9souWlmR00VWM70U1e9IlbZkttdnaXAm1xR15iZUvZBAzOxX
YUjrzFFRvUdinAS2soEtmhjO7tU9g3dLY7ZrVZ63WQukp1V6tFyInT8ib6+b48Re
hNIOv7KT52lf1aIkslyK1lx+6bIAeA4W8tpvBlSfA4nm1YDxt1thmljio8Wj6U2N
u4t72XdR/unXjMb38mdYWnBZHnol5TV08f3JAzZVqSliKlmAY/SnGvrApPItu+RL
BgxlSHKM1MzRawaeYfYibK7joZlr2optDcufgmr6X+E2RDpnZZaLkvzoLONvMfEu
I+HaIEA5W+uGUE7JDc88pttOhoQuL2FkYdjUd7UMn+H+ceH4DXclp5FpjrCUseJ2
tYWqflxwtJCw0hkU9VgXxcdeJdPM8UPL7CKvvkizJKEn2dCUDPOGLY5lbH/CYtFc
sEUC+4NfyOg2opnQ3i6V
=qcqv
-----END PGP SIGNATURE-----

This policy crawled by Onyphe on the 2021-01-02 is sorted as securitytxt.

FireBounty © 2015-2024

Legal notices | Privacy policy