79207 policies in database
Link to program      
2023-08-10
Infomaniak Bug Bounty program logo
Thank
Gift
HOF
Reward

Reward

Infomaniak Bug Bounty program

About us and our program

Us at Infomaniak

Infomaniak is Switzerland's largest web-hosting company, also offering live-streaming and video on demand services. Founded in 1994, Infomaniak is an independent company wholly owned by its founders and employees. Not only are 70% of their employees highly qualified engineers, they also focus systematically on internal development and open source solutions to design their products. Guaranteeing the security and confidentiality of the data entrusted to them is one of their priorities.

Infomaniak’s News

Hello Hunters ✋,

We are excited to announce the launch of our new product: MyKSuite! We invite all bug hunters to test this product here: https://www.infomaniak.com/fr/ksuite/myksuite

In addition, we are offering a 50% bonus for the first report found on MyKSuite! So don't hesitate to dive into testing this exciting new product.

We have also added a new feature: Multi-Login! We strongly encourage you to test this new feature and report any vulnerabilities you may find.

We look forward to seeing the results of your tests and are confident that you will help us improve our platform even further.

Happy hunting! ?

Hey hunters! ??

We've got some big news for you! ? We're jacking up the rewards for those juicy "High" EUR 2'000 ! and "Critical" EUR 5'000 ! vulnerabilities! ??

So come on, let's make our systems even more secure than ever before! ?

Thanks for being the best at what you do!

Happy hunting! ?

Hello Hunters ✋,

We have expanded our scope to include mobile and desktop applications. We invite you to join us in securing these platforms by finding any vulnerabilities they may have.

To sweeten the deal, the first valid report submitted on one of these new scopes will be eligible for a 50% bonus on top of the standard bounty amount. Don't miss out on this opportunity to increase your rewards while helping make the digital world a safer place.

Log into your YesWeHack account now and start exploring the new scopes. Happy hunting! ?

Infomaniak’s Challenges winners

  • Challenge #3 : MyKSuite... challenge in progress ⏳

  • Challenge #2 : Mobile and Desktop apps > Our challenge has been won by MrTuxracer, congratulation ??

  • Challenge #1 : Radio Streaming and Hosting Products ? ? > Our challenge has been won by two winners ex-aequo Rabhi and Ertugrul, congratulation on nice vulnerabilities in our radio product !

What we're looking for with this program

We are more than happy to be working with the YWH community to leverage its creativity and expertise in order to improve our products and assets' security. We try our best to provide secure solutions but as security is a constant struggle, we'd like your help in spotting anything that we might have missed !

We are particularly interested in any vulnerability involving the following :

  • Leaking of personal data
  • Horizontal / vertical privilege escalation
  • SQLi
  • Server misconfiguration
  • Server-Side Request Forgery
  • Insufficiently Protected Credentials
  • Network misconfiguration (between customers and internal servers)

Our program is constantly evolving and our scope expanding, do keep an eye out for new targets to test !

Program Rules

Testing Policy and Responsible Disclosure

Please adhere to the following rules while performing research on this program:

  • Denial of service (DoS) attacks on our applications, servers, networks or infrastructure are strictly forbidden.
  • Avoid tests that could cause degradation or interruption of our services.
  • Do not use automated scanners or tools that generate large amount of network traffic.
  • Do not leak, manipulate, or destroy any user data or files in any of our applications/servers.
  • Do not copy any files from our applications/servers and disclose them.
  • No vulnerability disclosure, full, partial or otherwise, is allowed.

Reward Eligibility and Amount

We are happy to thank everyone who submits valid reports which help us improve our security, however only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability (see below).
  • The report must contain the following elements:
    • Clear textual description of the vulnerability, how it can be exploited, the security impact it has on the application, its users and our organisation, and remediation advice on fixing the vulnerability
    • Proof of exploitation: screenshots demonstrating the exploit was performed, and showing the final impact
    • Provide complete steps with the necessary information to reproduce the exploit, including (if necessary) code snippets, payloads, commands etc
  • You must not break any of the testing policy rules listed above.
  • You must not be a former or current employee of our organisation or one of its contractors.
  • If you find the same vulnerability several times, please create only one report and eventually use comments. You'll be rewarded according to your findings.
  • The triage team will use the "One Fix One Reward" process: if two or more endpoints/forms use the same code base and a single fix can be deployed to fix all the other weaknesses, only one endpoint will be considered as eligible for a reward and other reports will be closed as Informative/Duplicate.

Reward amounts are based on:

  • Reward grid of the report's scope
  • CVSS scoring and actual business impact of the vulnerability upon performing risk analysis

Specific provisions and testing conditions

About Denial of service

Given our product and context, our customers expect the highest level of availability. Thus DoS/DDoS attacks or brute force attacks are not allowed and we ask you to avoid any test that might disturb our service and customer's servers.

In doubt, please reach out to the team at security@infomaniak.com

Openstack products are Out of scope

We use Openstack platform to provide instances, network, databases. You can create resources and find misconfigurations, unprotected data, etc.
Vulnerabilities like XSS in Openstack dashboard (Horizon) are out of scopes.

Vulnerabilities on Ticketing service

We allow our customers to inject JavaScript and html code into certain parts of the online ticketting service shop so that they can add google tag tracking for instance, or external content. This is of course an intended behavior even though it could allow them to inject an XSS payload for example.

Thus, we won’t accept and consider for reward reports linked to vulnerabilities introduced through the ticketing service editor, or another ticketing page/feature by an administrator/technical/sales users that are targeting their own website’s users.

Vulnerabilities on Page editor and site creator

In order to allow full customization of their websites Customers with administrator rights can edit or create pages with Page editor or Site creator and are allowed to inject JavaScript or html code for instance. This is of course an intended behavior even though it could allow them to inject an XSS payload for example.

Thus, we won’t accept and consider for reward reports linked to vulnerabilities introduced through Page editor or Site creator by a website administrator that are targeting their own website’s users.

HTML Injection in emails

These vulnerabilities are not currently of interest to the company and have been temporarily excluded. We are planning to change our templating system.

Business logic

We do not verify users' emails because we aim to provide a free and seamless user experience. Infomaniak offers a kCheck application and feature that can verify user identities in cases where we observe disruptive behavior. This helps us identify and block suspicious users.

Business logic Errors

Vulnerabilities of the 'Business Logic Error' type are not considered within the scope of this bug bounty program. Only serious cases involving leaks of personally identifiable information (PII) or leaks of customer or confidential data will be considered eligible for a reward. Bugs related to user rights on a product, between different products, or to restricted functionality limitations of a product will not be taken into account.

Broken Access Control

Broken Access Control vulnerabilities linked to inconsistencies in rights between administrators, employees or external users are no longer considered within the scope of the programme. Only critical cases involving leaks of information and significant personal data. Or a major impact on the business or financial aspects of our products.

Out of scope services

The following services are out of the scope of this program :

  • Housing
  • Newsletter
  • Very high availability Hosting
  • Synology
  • Jelastic cloud
  • Safe tracing
  • Web FTP https://manager.infomaniak.com/ftp
  • Debian community servers : example with buster-.infomaniak.ch, bookworm-.infomaniak.ch

Site creator scope

We provide Site Creator instances for hunters to test:

https://5k8vrbdyje.infomaniak.site
https://tb7pxbdyjg.infomaniak.site
https://fv3lfbdyjh.infomaniak.site
https://l75pvbdyjo.infomaniak.site

Our customers' site creators are not part of the programme and we ask you not to test them.

Mobile and desktop applications

Android kDrive https://github.com/Infomaniak/android-kDrive
Android kMail https://github.com/Infomaniak/android-kMail

iOS kDrive https://github.com/Infomaniak/ios-kDrive
iOS kMail https://github.com/Infomaniak/ios-kMail

Desktop kDrive https://github.com/Infomaniak/desktop-kDrive

Reports of leaks and exposed credentials

We are open to some types of reports related to exposed secrets, credentials or information.
Please pay attention to our list of Qualifying/Non-Qualifying vulnerabilities, as well as our Scope and the following rules.

In order not to encourage dark and grey economies, in particular the purchase, resale and trade of identifiers or stolen information, as well as all types of dangerous behavior (e.g. social engineering, ...), we will not accept or reward any report based on information whose source is not the result of failure on the part of our organization or one of our employees/service providers

Disclosed information like credentials, emails, calendar invitation, guest invitation link, swisstransfer public link, kdrive public link, vod public link from this sources are not accepted :

  • archive.org
  • wayback machine
  • virusTotal
  • google dorking

Eligible reports

Reports of exposed secrets, credentials and sensitive information will be considered eligible if it complies with the following:

  • The source of exposure/leak is under our company’s control, directly or indirectly, e.g. stolen information or bundled information from a random source is not eligible.
  • The exposed information has been verified (or tested) and confirmed

If you identify a source (under our control) that is leaking multiple data, we kindly ask you to report it in a single report and we will consider the impact based on the nature and depth of the exposed data.

To summarize our policy, you may refer to this table :

Source of leak is in-scope Source of leak belongs to our organisation but is out-of-scope Source of leak does not belong to our organisation and is out-of-scope
Impact is in-scope (e.g. valid credentials on an in-scope asset) Eligible Eligible Not Eligible
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) Eligible Eligible Not Eligible

Important precautions and limitations

As a complement to the Program’s rules and testing policy :

  • DO NOT alter compromised accounts by creating, deleting or modifying any data
  • DO NOT use compromised accounts to search for post-auth vulnerabilities (they won’t be eligible anyway)
  • DO NOT include Personally Identifiable Information (PII) in your report and please REDACT/OBFUSCATE the PII that is part of your PoC (screenshot, server response, JSON file, etc.) as much as possible.
  • In case of exposed credentials or secrets, limit yourself to verifying the credentials validity
  • In case of sensitive information leak, DO NOT extract/copy every document or data that is exposed and limit yourself to describe and list what is exposed.

In Scope

Scope Type Scope Name
android_application

https://play.google.com/store/apps/details?id=com.infomaniak.drive

android_application

https://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_US

api

api.infomaniak.com

application

https://github.com/Infomaniak/desktop-kDrive

ios_application

https://apps.apple.com/app/infomaniak-kdrive/id1482778676

ios_application

https://apps.apple.com/fr/app/infomaniak-mail/id1622596573

mobile_applications

ai-tools.infomaniak.com

web_application

*.kdrive.infomaniak.com

web_application

login.infomaniak.com

web_application

shop.infomaniak.com

web_application

*.kchat.infomaniak.com

web_application

calendar.infomaniak.com

web_application

contacts.infomaniak.com

web_application

etickets.infomaniak.com

web_application

infomaniak.events

web_application

mail.infomaniak.com

web_application

sms.infomaniak.com

web_application

swiss-backup*.infomaniak.com

web_application

vod.infomaniak.com

web_application

welcome.infomaniak.com

web_application

www.swisstransfer.com

web_application

www.infomaniak.com

web_application

developer.infomaniak.com

web_application

kmeet.infomaniak.com

web_application

*.vod2.infomaniak.com

web_application

player-radio.infomaniak.com

web_application

ix2smbdyjt.infomaniak.site

web_application

5k8vrbdyje.infomaniak.site

web_application

fv3lfbdyjh.infomaniak.site

web_application

l75pvbdyjo.infomaniak.site

web_application

chk.infomaniak.com

web_application

manager.infomaniak.com/v3/*

web_application

invitation.infomaniak.com

web_application

kpaste.infomaniak.com

web_application

sync.infomaniak.com

web_application

storage*.infomaniak.com

Out of Scope

Scope Type Scope Name
undefined

Assets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for reward

undefined

We do not manage Open Stack dashboard which is therefore out of scope

undefined

ov-XX.infomaniak.ch and od-XX.infomaniak.ch sub domains

undefined

Jelastic subdomains : .jcloud.ik-server.com, .jpc.infomaniak.com, *.jpe.infomaniak.com

undefined

User email verification

web_application

https://api.pub1.infomaniak.cloud

web_application

newsletter.infomaniak.com

web_application

This domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. This is only office application, an external app to open MS office documents.

web_application

FTP credentials from our customers, like *.ftp.infomaniak.com

web_application

MySQL credentials from our customers, like *.myd.infomaniak.com

web_application

VPS instances from our customers, like *.vps.infomaniak.com


This program have been found on Yeswehack on 2023-08-10.

FireBounty © 2015-2025

Legal notices | Privacy policy