52212 policies in database
Link to program      
2021-04-02
backmarket.com logo
Thank
Gift
HOF
Reward

backmarket.com

A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512


# Thinking you found a security vulnerability? Let's talk and take a responsible disclosure path together.
# In a nutshell, we are interested in real vulnerabilities that could substantially affect the confidentiality or
# integrity of Back Market's Customers and/or Merchants data, not output of automated scanners.

# Following vulnerabilities are examples of vulnerabilities that are *out-of-scope*:
# * reports from automated tools or scans
# * lack of, or insufficient, rate limiting on an endpoint
# * outdated software without any noteworthy vulnerability
# * missing security headers which do not lead directly to a vulnerability
# * lack of CSRF tokens which do not lead directly to a vulnerability
# * missing security best practice which do not lead directly to a vulnerability

# When submitting a vulnerability report, please always ensure to provide at least *precise* and detailed steps to
# reproduce all described attack scenarios. Additionally, screenshots, samples, scripts, ... are all helpful.
# Without precise information, we won't be able to qualify the submission as an exploitable security vulnerability.
# Also, please be realistic: bugs requiring exceedingly unlikely user interaction such as entering manually an
# attack payload, going through forged third party phishing pages, etc. may realistically not meet the bar.
# Due to large amount of emails, we might not be able to respond to all reports for out-of-scope vulnerabilities.
Contact: mailto:security@backmarket.com

# Sensitive information require adequate protection, and cleartext in email body does not serve that objective.
# Therefore, please always encrypt your vulnerability report and provide it as an email attachment.
Encryption: https://www.backmarket.com/.well-known/security-pubkey.txt
Encryption: https://keys.openpgp.org/search?q=security@backmarket.com
Encryption: openpgp4fpr:2cebfa0bd82d37009ab2add25edd605bb8f4c0dd

# Back Market is continually looking for new talents, this might be a good opportunity to reach out!
Hiring: https://jobs.backmarket.com/

# You know how it works, right? Past the expiration date, consuming info from this file is at your own risk.
Expires: Tue, 01 Aug 2023 00:00:00 -0000

-----BEGIN PGP SIGNATURE-----

iQJMBAEBCgA2FiEELOv6C9gtNwCasq3SXt1gW7j0wN0FAmLu97oYHHNlY3VyaXR5
QGJhY2ttYXJrZXQuY29tAAoJEF7dYFu49MDdDosQAI77qXTGsyB24LP6WNNJ+sdN
7Gealt2nBWO3tkeWk32rL31OcXvLUui9fFYPYsSB+L7x6wylpNJDYW3KqCFL1x4h
mPGZTKui4kVCygdjPIm9DCrMIZOLGMoccojdmT1EN6gS4lx/IqRW1zN7i7t+QUtB
ntTWF7UDJvrP0B4X5d3hZcaVYVFfUryFN59ELNOYKoogZPDXcUPwrMEjAI7MJ0XK
Dr3FWBsMhGuTkL5izmVL0Hw0C+7G3b1MN5J3oyskgEMarEYHDWB3UP/R68ZCsPC4
h8KVJuD6WDy6KAk/47bMw0UFhd5miME569CFdKoKe4redpcibXzoUEmOACRJUeXZ
65n9PyaPSP7gF3hGOwRVECEX12nMweMhTA3rehOmJ0GaaYKHvHs+sl1sDtGKAhRO
Aw/3iJltz4/z6D9en6iAPg4l1J8iVhKGovj5NO8BJZaH5uQ1s7W5WAVDx5+tuiip
CMYheA8RudSr5hAl8uGdiTvDoLjjCaWgkncyawlsY2qRxRI8PGEM9pv/GJxCj1UI
PyDjRh/jDbsk4t6pt0g4UON+QFaXethgzpO/4qpatHbB8l5eMswd+mS10KQi1CRq
xswN4WzfElGfPLUXZdwyF5Oqoxalm6qky5N7JEAcVZCcD+aqCjfiZV/+cZyIxuBH
o4RNznHyashJmyRzXAlN
=7XAB
-----END PGP SIGNATURE-----

This policy crawled by Onyphe on the 2021-04-02 is sorted as securitytxt.

FireBounty © 2015-2024

Legal notices | Privacy policy