SEGA Europe Limited (“SEGA”) aims to provide safe and secure products and services to our gaming community. We value the role that the security community play and appreciate the importance of providing quick and effective means for you to contact us regarding potential vulnerabilities relevant to our customers’ privacy or the confidentiality, integrity or availability of our systems.
SEGA will use reasonable effort to meet the following SLAs for hackers participating in our Responsible Disclosure Programme:
| Type of Response | SLA in business days |
|----------|--------------------|
| First Response | 2 days |
| Time to Triage | 2 days |
| Time to Resolution | depends on severity and complexity |
We’ll try to keep you informed about our progress throughout the process.
You have been invited to participate in this Responsible Disclosure Programme (the “Programme”) for the sole purpose of identifying bugs and security vulnerabilities within our applications, websites, network and information technology services, processes and procedures (the “SEGA Systems”).
Before participating in this Programme, please read the following guidelines. By participating in the Programme, you may gain access to certain proprietary and confidential information (the “Confidential Information”) on the SEGA Systems. The Confidential Information should be held by you in the strictest confidence and you agree not to use, reproduce, or redistribute any of the SEGA Confidential Information except as expressly permitted in the Disclosure Policy. SEGA shall not be liable to you in any way for any loss or damage of any kind resulting from your access to the Confidential Information and/or participation in the security vulnerabilities programme.
If you do not agree with SEGA’s Responsible Disclosure Policy and the Programme Rules, please do not participate in our Responsible Disclosure Programme.
In addition to the Disclosure Policy, you shall comply with HackerOne's disclosure guidelines (https://www.hackerone.com/disclosure-guidelines).
The Confidential Information may contain information and assets that are protected by UK copyright laws, international copyright treaties and conventions and other laws. You acknowledge and agree that you shall have no ownership or other proprietary interest in the Confidential Information, and you further acknowledge and agree that all such rights in the Confidential Information shall forever be owned by and inure to the benefit of SEGA and/or its licensees and licensors.
By opting to participate in the security vulnerabilities programme, you do so at your own risk.
This is a private programme, please do not discuss this programme or any vulnerabilities (even resolved ones) outside of the programme without express consent from SEGA.
Should SEGA process any personal data relating to you with respect to your participation in the security vulnerabilities programme, it shall do so in accordance with the Privacy Policy available at: www.sega.co.uk/privacy.
You agree that any unauthorised use or disclosure of the Confidential Information shall cause SEGA irreparable harm and SEGA reserves all its legal rights in this regard.
At all times, you should act responsibly and in the best interests of SEGA and our customers, and in accordance with the following:
• Do act in good faith
• Do not break the law
• Do not perform high volume scans that may interrupt services.
• Do not use social engineering techniques against our customers or staff
• Do not put SEGA, or our customer data or the SEGA Systems at risk
• Do provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged
• Do provide a description of your assessment of the extent and impact of the vulnerability
• Do provide your contact details so that we can follow up with you
• Do provide a detailed and complete submission (masking or encrypting if necessary)
• Do reference existing vulnerability information where relevant
• Do ensure that you comply with the HackerOne disclosure guidelines
• Do submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact. When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced). Multiple vulnerabilities caused by one underlying issue will be treated as one valid report
• Do not use social engineering techniques (e.g., phishing, vishing, smishing). SEGA act decisively on attacks and extortion attempts, and we will report our concerns to the police where we believe such an attack or extortion attempt has been made
• Do make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the service.
• Do ensure that you only interact with accounts you own or with the explicit permission of the account holder
Clickjacking on pages with no sensitive actions
Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
Attacks requiring MITM or physical access to a user's device.
Previously known vulnerable libraries without a working Proof of Concept.
Comma Separated Values (CSV) injection without demonstrating a vulnerability.
Missing best practices in SSL/TLS configuration.
Any activity that could lead to the disruption of our service (DoS).
Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
Rate limiting or brute-force issues on non-authentication endpoints
Missing best practices in Content Security Policy.
Missing HTTP only or Secure flags on cookies
Missing email best practices (Invalid, incomplete, or missing SPF/DKIM/DMARC records, etc.)
Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]
Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application, or server errors).
Tabnabbing
Open redirect - unless an additional security impact can be demonstrated
Issues that require unlikely user interaction
Self XSS or XSS that affecting out-of-date browsers.
Please note that SEGA does not respond to generic communications which are unrelated, vague, or with no direct evidence of a vulnerability relating to the SEGA Systems.
Thank you for helping keep SEGA and our users safe!
Scope Type | Scope Name |
---|---|
ios_application | Two Point Studios |
ios_application | Amplitude Studios |
ios_application | Hardlight Studios |
other | SEGA Europe |
other | Creative Assembly |
other | Sports Interactive |
other | Relic Entertainment |
web_application | games2gether.com |
web_application | community.twopointcounty.com |
web_application | community.companyofheroes.com |
Scope Type | Scope Name |
---|---|
other | SEGA Japan |
This policy crawled by Onyphe on the 2021-11-23 is sorted as bounty.
FireBounty © 2015-2024