InMobi is the world's leading Marketing Cloud, driving real connections between brands and consumers. We create new paths for brands to understand, identify, engage and acquire consumers by leveraging our exclusive access to mobile intelligence and technology platforms.
As a leading technology company founded in 2007, InMobi has been recognized as a 2019 CNBC Disruptor 50 company and as Fast Company's 2018 Most Innovative Companies. For more information, visit inmobi.com.
InMobi Group looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe.
Please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.
Follow HackerOne's disclosure guidelines.
InMobi Group will make a best effort to meet the following SLAs for hackers participating in our program:
| Type of Response | SLA in business days |
| --------------- | --------------- |
| First Response | 2 days |
| Time to Triage | 5 days |
| Time to Resolution | depends on severity and complexity |
We’ll try to keep you informed about our progress throughout the process.
Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.
Submit one vulnerability per the report, unless you need to chain vulnerabilities to provide impact.
When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced).
Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
Social engineering (e.g. phishing, vishing, smishing) is prohibited.
Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with the explicit permission of the account holder.
When reporting vulnerabilities, please consider attack scenario/exploitability, and the security impact of the bug. The following issues are considered out of scope:
Blind SSRF
Known issues
Rate limiting (Unless which impacts severe threat to data, business loss)
Open redirects
Clickjacking and issues only exploitable through clickjacking
Vulnerabilities that are exploitable only via a MITM attack
Patches that were released within the last 30 days.
Networking issues or industry standards.
Password complexity.
Email related: SPF or DMARC records, Gmail "+" and "." acceptance, Email bombs, Unsubscribing from marketing emails.
Information Leakage: Descriptive error messages (e.g. Stack Traces, application or server errors), HTTP 404 codes/pages or other HTTP non-200 codes/pages, Fingerprinting/Banner grabbing on common/public services, Disclosure of known public files or directories, (e.g. robots.txt), Cacheable SSL pages.
CSRF on forms that are available to anonymous users (e.g. the contact form, sign-up form).
Logout Cross-Site Request Forgery (logout CSRF).
Weak CSRF in the APIs.
Forgot Password page brute force and account lockout not enforced.
Lack of Captcha.
Presence of application or web browser "autocomplete" or "save password" functionality.
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep InMobi Group and our users safe!
Scope Type | Scope Name |
---|---|
android_application | com.roposo.android |
android_application | com.o1 |
android_application | com.koral |
android_application | com.o1.dash101 |
ios_application | 950273328 |
ios_application | 1050971067 |
web_application | *.inmobi.com |
web_application | *.dash101.com |
web_application | *.shop101.com |
web_application | *.glance.inmobi.com |
web_application | *.glance.world |
web_application | *.glance.app |
web_application | *.glance.com |
web_application | *.koralapp.com |
web_application | *.roposo.com |
web_application | mydash101.com |
Firebounty have crawled on 2021-12-15 the program InMobi on the platform Hackerone.
FireBounty © 2015-2024