52235 policies in database
Link to program      
2021-12-15
InMobi logo
Thank
Gift
HOF
Reward

InMobi

About Us

InMobi is the world's leading Marketing Cloud, driving real connections between brands and consumers. We create new paths for brands to understand, identify, engage and acquire consumers by leveraging our exclusive access to mobile intelligence and technology platforms.

As a leading technology company founded in 2007, InMobi has been recognized as a 2019 CNBC Disruptor 50 company and as Fast Company's 2018 Most Innovative Companies. For more information, visit inmobi.com.

InMobi Group looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe.

Disclosure Policy

  • Please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.

  • Follow HackerOne's disclosure guidelines.

Response Targets

InMobi Group will make a best effort to meet the following SLAs for hackers participating in our program:

| Type of Response | SLA in business days |

| --------------- | --------------- |

| First Response | 2 days |

| Time to Triage | 5 days |

| Time to Resolution | depends on severity and complexity |

We’ll try to keep you informed about our progress throughout the process.

Program Rules

  • Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.

  • Submit one vulnerability per the report, unless you need to chain vulnerabilities to provide impact.

  • When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced).

  • Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.

  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with the explicit permission of the account holder.

Out of scope vulnerabilities

When reporting vulnerabilities, please consider attack scenario/exploitability, and the security impact of the bug. The following issues are considered out of scope:

General

  • Blind SSRF

  • Known issues

  • Rate limiting (Unless which impacts severe threat to data, business loss)

  • Open redirects

  • Clickjacking and issues only exploitable through clickjacking

  • Vulnerabilities that are exploitable only via a MITM attack

System-Related

  • Patches that were released within the last 30 days.

  • Networking issues or industry standards.

  • Password complexity.

  • Email related: SPF or DMARC records, Gmail "+" and "." acceptance, Email bombs, Unsubscribing from marketing emails.

  • Information Leakage: Descriptive error messages (e.g. Stack Traces, application or server errors), HTTP 404 codes/pages or other HTTP non-200 codes/pages, Fingerprinting/Banner grabbing on common/public services, Disclosure of known public files or directories, (e.g. robots.txt), Cacheable SSL pages.

CSRF

  • CSRF on forms that are available to anonymous users (e.g. the contact form, sign-up form).

  • Logout Cross-Site Request Forgery (logout CSRF).

  • Weak CSRF in the APIs.

Login/Session related

  • Forgot Password page brute force and account lockout not enforced.

  • Lack of Captcha.

  • Presence of application or web browser "autocomplete" or "save password" functionality.

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Thank you for helping keep InMobi Group and our users safe!

In Scope

Scope Type Scope Name
android_application

com.roposo.android

android_application

com.o1

android_application

com.koral

android_application

com.o1.dash101

ios_application

950273328

ios_application

1050971067

web_application

*.inmobi.com

web_application

*.dash101.com

web_application

*.shop101.com

web_application

*.glance.inmobi.com

web_application

*.glance.world

web_application

*.glance.app

web_application

*.glance.com

web_application

*.koralapp.com

web_application

*.roposo.com

web_application

mydash101.com


Firebounty have crawled on 2021-12-15 the program InMobi on the platform Hackerone.

FireBounty © 2015-2024

Legal notices | Privacy policy