Infomaniak is Switzerland's largest web-hosting company, also offering live-streaming and video on demand services. Founded in 1994, Infomaniak is an independent company wholly owned by its founders and employees. Not only are 70% of their employees highly qualified engineers, they also focus systematically on internal development and open source solutions to design their products. Guaranteeing the security and confidentiality of the data entrusted to them is one of their priorities.
Hello Hunters ✋,
We are excited to announce the launch of our new product: MyKSuite! We invite all bug hunters to test this product here: https://www.infomaniak.com/fr/ksuite/myksuite
In addition, we are offering a 50% bonus for the first report found on MyKSuite! So don't hesitate to dive into testing this exciting new product.
We have also added a new feature: Multi-Login! We strongly encourage you to test this new feature and report any vulnerabilities you may find.
We look forward to seeing the results of your tests and are confident that you will help us improve our platform even further.
Happy hunting! ?
Hey hunters! ??
We've got some big news for you! ? We're jacking up the rewards for those juicy "High" EUR 2'000 ! and "Critical" EUR 5'000 ! vulnerabilities! ??
So come on, let's make our systems even more secure than ever before! ?
Thanks for being the best at what you do!
Happy hunting! ?
Hello Hunters ✋,
We have expanded our scope to include mobile and desktop applications. We invite you to join us in securing these platforms by finding any vulnerabilities they may have.
To sweeten the deal, the first valid report submitted on one of these new scopes will be eligible for a 50% bonus on top of the standard bounty amount. Don't miss out on this opportunity to increase your rewards while helping make the digital world a safer place.
Log into your YesWeHack account now and start exploring the new scopes. Happy hunting! ?
Challenge #3 : MyKSuite... challenge in progress ⏳
Challenge #2 : Mobile and Desktop apps > Our challenge has been won by MrTuxracer, congratulation ??
Challenge #1 : Radio Streaming and Hosting Products ? ? > Our challenge has been won by two winners ex-aequo Rabhi and Ertugrul, congratulation on nice vulnerabilities in our radio product !
We are more than happy to be working with the YWH community to leverage its creativity and expertise in order to improve our products and assets' security. We try our best to provide secure solutions but as security is a constant struggle, we'd like your help in spotting anything that we might have missed !
We are particularly interested in any vulnerability involving the following :
Our program is constantly evolving and our scope expanding, do keep an eye out for new targets to test !
Please adhere to the following rules while performing research on this program:
We are happy to thank everyone who submits valid reports which help us improve our security, however only those that meet the following eligibility requirements may receive a monetary reward:
Reward amounts are based on:
Given our product and context, our customers expect the highest level of availability. Thus DoS/DDoS attacks or brute force attacks are not allowed and we ask you to avoid any test that might disturb our service and customer's servers.
In doubt, please reach out to the team at security@infomaniak.com
We use Openstack platform to provide instances, network, databases. You can create resources and find misconfigurations, unprotected data, etc.
Vulnerabilities like XSS in Openstack dashboard (Horizon) are out of scopes.
We allow our customers to inject JavaScript and html code into certain parts of the online ticketting service shop so that they can add google tag tracking for instance, or external content. This is of course an intended behavior even though it could allow them to inject an XSS payload for example.
Thus, we won’t accept and consider for reward reports linked to vulnerabilities introduced through the ticketing service editor, or another ticketing page/feature by an administrator/technical/sales users that are targeting their own website’s users.
In order to allow full customization of their websites Customers with administrator rights can edit or create pages with Page editor or Site creator and are allowed to inject JavaScript or html code for instance. This is of course an intended behavior even though it could allow them to inject an XSS payload for example.
Thus, we won’t accept and consider for reward reports linked to vulnerabilities introduced through Page editor or Site creator by a website administrator that are targeting their own website’s users.
These vulnerabilities are not currently of interest to the company and have been temporarily excluded. We are planning to change our templating system.
We do not verify users' emails because we aim to provide a free and seamless user experience. Infomaniak offers a kCheck application and feature that can verify user identities in cases where we observe disruptive behavior. This helps us identify and block suspicious users.
Vulnerabilities of the 'Business Logic Error' type are not considered within the scope of this bug bounty program. Only serious cases involving leaks of personally identifiable information (PII) or leaks of customer or confidential data will be considered eligible for a reward. Bugs related to user rights on a product, between different products, or to restricted functionality limitations of a product will not be taken into account.
Broken Access Control vulnerabilities linked to inconsistencies in rights between administrators, employees or external users are no longer considered within the scope of the programme. Only critical cases involving leaks of information and significant personal data. Or a major impact on the business or financial aspects of our products.
The following services are out of the scope of this program :
We provide Site Creator instances for hunters to test:
https://5k8vrbdyje.infomaniak.site
https://tb7pxbdyjg.infomaniak.site
https://fv3lfbdyjh.infomaniak.site
https://l75pvbdyjo.infomaniak.site
Our customers' site creators are not part of the programme and we ask you not to test them.
Android kDrive https://github.com/Infomaniak/android-kDrive
Android kMail https://github.com/Infomaniak/android-kMail
iOS kDrive https://github.com/Infomaniak/ios-kDrive
iOS kMail https://github.com/Infomaniak/ios-kMail
Desktop kDrive https://github.com/Infomaniak/desktop-kDrive
We are open to some types of reports related to exposed secrets, credentials or information.
Please pay attention to our list of Qualifying/Non-Qualifying vulnerabilities, as well as our Scope and the following rules.
In order not to encourage dark and grey economies, in particular the purchase, resale and trade of identifiers or stolen information, as well as all types of dangerous behavior (e.g. social engineering, ...), we will not accept or reward any report based on information whose source is not the result of failure on the part of our organization or one of our employees/service providers
Disclosed information like credentials, emails, calendar invitation, guest invitation link, swisstransfer public link, kdrive public link, vod public link from this sources are not accepted :
Reports of exposed secrets, credentials and sensitive information will be considered eligible if it complies with the following:
If you identify a source (under our control) that is leaking multiple data, we kindly ask you to report it in a single report and we will consider the impact based on the nature and depth of the exposed data.
Source of leak is in-scope | Source of leak belongs to our organisation but is out-of-scope | Source of leak does not belong to our organisation and is out-of-scope | |
---|---|---|---|
Impact is in-scope (e.g. valid credentials on an in-scope asset) | Eligible | Eligible | Not Eligible |
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) | Eligible | Eligible | Not Eligible |
As a complement to the Program’s rules and testing policy :
Scope Type | Scope Name |
---|---|
android_application | https://play.google.com/store/apps/details?id=com.infomaniak.drive |
android_application | https://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_US |
api | api.infomaniak.com |
application | https://github.com/Infomaniak/desktop-kDrive |
ios_application | https://apps.apple.com/app/infomaniak-kdrive/id1482778676 |
ios_application | https://apps.apple.com/fr/app/infomaniak-mail/id1622596573 |
mobile_applications | ai-tools.infomaniak.com |
web_application | *.kdrive.infomaniak.com |
web_application | login.infomaniak.com |
web_application | shop.infomaniak.com |
web_application | *.kchat.infomaniak.com |
web_application | calendar.infomaniak.com |
web_application | contacts.infomaniak.com |
web_application | etickets.infomaniak.com |
web_application | infomaniak.events |
web_application | mail.infomaniak.com |
web_application | sms.infomaniak.com |
web_application | swiss-backup*.infomaniak.com |
web_application | vod.infomaniak.com |
web_application | welcome.infomaniak.com |
web_application | www.swisstransfer.com |
web_application | www.infomaniak.com |
web_application | developer.infomaniak.com |
web_application | kmeet.infomaniak.com |
web_application | *.vod2.infomaniak.com |
web_application | player-radio.infomaniak.com |
web_application | ix2smbdyjt.infomaniak.site |
web_application | 5k8vrbdyje.infomaniak.site |
web_application | fv3lfbdyjh.infomaniak.site |
web_application | l75pvbdyjo.infomaniak.site |
web_application | chk.infomaniak.com |
web_application | manager.infomaniak.com/v3/* |
web_application | invitation.infomaniak.com |
web_application | kpaste.infomaniak.com |
web_application | sync.infomaniak.com |
web_application | storage*.infomaniak.com |
Scope Type | Scope Name |
---|---|
undefined | Assets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for reward |
undefined | We do not manage Open Stack dashboard which is therefore out of scope |
undefined | ov-XX.infomaniak.ch and od-XX.infomaniak.ch sub domains |
undefined | Jelastic subdomains : .jcloud.ik-server.com, .jpc.infomaniak.com, *.jpe.infomaniak.com |
undefined | User email verification |
web_application | https://api.pub1.infomaniak.cloud |
web_application | newsletter.infomaniak.com |
web_application | This domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. This is only office application, an external app to open MS office documents. |
web_application | FTP credentials from our customers, like *.ftp.infomaniak.com |
web_application | MySQL credentials from our customers, like *.myd.infomaniak.com |
web_application | VPS instances from our customers, like *.vps.infomaniak.com |
This program have been found on Yeswehack on 2023-08-10.
FireBounty © 2015-2025