Tencent looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe. If you believe you have discovered a vulnerability, kindly disclose to us responsibly via the Tencent Security Response Centre (TSRC).
This Bounty Policy governs your participation in the bounty program and forms part of the Tencent Security Response Center Terms of Service.
Note: For a smooth payment, make sure to use the same email address on both TSRC and YesWeHack. Eligible reports will be imported to the program and hunters will be able to claim them. Once claimed, these reports will be eligible for a payment.
For any questions or clarifications, you may contact the Tencent Security Team at security@tencent.com.
Other links:
The classification of a vulnerability (Critical, High, Moderate or Low as described below), whether a product or application is in scope of the bounty program and its classification (core, important, and other in-scope), and whether to grant a monetary reward and its amount will be within the sole discretion of the Tencent Security Team, based on a number of factors including, without limitation, quality of the report, severity of the vulnerability, reproducibility of the vulnerability, its
impact on our users and other products and services, ease of exploitation and many other factors.
Any design or implementation issue regarding any qualifying product that is reproducible and substantially affects the security of Tencent users is likely to be in scope for the program.
However, reports and researchers must meet the following requirements to be eligible to receive a monetary reward through YesWeHack platform:
You grant Tencent a non-exclusive, royalty-free, irrevocable, perpetual, transferable, worldwide license (with the right to sublicense) to copy, reproduce, use, modify, test, create derivative works (including commercial products) based upon, distribute, publish, display and otherwise exploit your reports and other information you provide to us under this Agreement.
Rewards are stated in USD.
All reports will be reviewed based on the impact and severity of the reported vulnerability. Any qualifying report that results in a change being made will at a minimum receive the Hall of Fame recognition.
The main categories of vulnerabilities that we are primarily concerned about are:
Products, services and applications distributed and made available in any form by or on behalf of Tencent and described in "Core Products" and "Other In-Scope Products" below are in scope. For more information about our products and services, please visit https://www.tencent.com/en-us/business.html.
It includes the majority of Tencent's products and businesses, such as Tencent Game Helper (腾讯游戏助手), Tencent Ride Code Mini Program(腾讯乘车码小程序), QQ Music and other products, including but not limited to mobile applications, clients, mini programs, web sites, hardware, IoT, server services, and other product models.
Only vulnerabilities affecting the platform itself and IP owned by Tencent will be accepted. If an IP belongs to Tencent Cloud external customer, it is not considered in scope.
You can use a QQ or Wechat account to log into all Tencent's products and services. 1. To register a QQ account, please go to https://ssl.zc.qq.com/v3/index-en.html?type=0 and follow the instructions. 2. To register a WeChat account, please download an WeChat app from App store or through Android system, then follow the registration guide. Once you have a QQ or WeChat account, you can start testing.
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope (either ineligible or false positives):
We have set up a "demo" service for SSRF testing. If you believe you have an SSRF in production, please use either of the following IP/port combinations for testing:
This service will accept HTTP requests to any endpoint, of any request type, and will return a secret token in both headers and response body.
| Scope Type | Scope Name |
|---|---|
| web_application | Core Assets In-Scope Products (for the full list please visit https://en.security.tencent.com/index.php/policy) |
| web_application | Non Core Assets In-Scope Products (for the full list please visit https://en.security.tencent.com/index.php/policy) |
| Scope Type | Scope Name |
|---|---|
| undefined | Please note that the vulnerabilities reported for the following assets will not be eligible for bounties. |
| undefined | Notes about Tencent Cloud (cloud.tencent.com as included in .tencent.com) |
| undefined | Only vulnerabilities affecting the platform itself and IP owned by Tencent will be accepted. If an IP belongs to Tencent Cloud external customer, it is not considered in scope. |
| web_application | *.qzoneapp.com |
| web_application | *. myqcloud.com |
| web_application | Third-party applications and websites |
This program crawled on the 2023-04-26 is sorted as bounty.
FireBounty © 2015-2026