52235 policies in database
Link to program      
2020-06-12
bitdegree.org logo
Thank
Gift
HOF
Reward

bitdegree.org

A vulnerability disclosure policy (VDP), also referred to as a responsible disclosure policy, describes how an organization will handle reports of vulnerabilities submitted by ethical hackers. A VDP must thus be easily identifiable via a simple way, a security.txt notice.

Contact: security@bitdegree.org
Preferred-Languages: en

BitDegree

BitDegree Responsible Disclosure Policy and Bug Rewards Program

PLEASE READ THIS AGREEMENT CAREFULLY, AS IT CONTAINS IMPORTANT INFORMATION REGARDING YOUR LEGAL RIGHTS AND REMEDIES.

RESPONSIBLE DISCLOSURE POLICY:
BitDegree encourages the responsible disclosure of security vulnerabilities in our services or on our website. In order to facilitate the responsible disclosure of security vulnerabilities, we agree that if, in our sole discretion, we conclude that a disclosure meets all of the guidelines of the BitDegree Bug Rewards Program, BitDegree will not bring any private or criminal legal action against the disclosing party.

BUG REWARDS PROGRAM
BitDegree offers monetary bounties for the responsible disclosure of certain qualifying security vulnerabilities. Our Bug Rewards Program works as follows

SERVICES IN SCOPE:
Only the www.bitdegree.org web services are within scope for purposes of the BitDegree Bug Rewards Program.

QUALIFYING VULNERABILITIES:
BitDegree will accept a report of any vulnerability that substantially affects the confidentiality or integrity of any eligible BitDegree service. Eligible vulnerabilities include, but are not limited to:

Authentication and Authorization Flaws
Remote Code Execution
SQL Injection
Directory Traversal
Privilege Escalation

NON-QUALIFYING VULNERABILITIES:
Any domain not contained within www.bitdegree.org is out of scope for the purposes of the Bug Rewards Program, third-party programs and plug-ins.

The following actions do not qualify for the Bug Rewards Program and should not be tested by researchers participating in the Program:

DoS, brute force, user enumeration or DDoS attacks
Cross Site Scripting (XSS)
Cross Site Request Forgery (CSRF)
Click-jacking
Physical attacks
Phishing attacks
Any bug that relies on Social engineering
CRIME/BEAST attacks
Logout CSRF
Banner or version disclosures
Missing SPF records
Directory listing (unless sensitive data can be found)
Blackhat SEO techniques
Any bug that relies upon an outdated browser
BitDegree will not accept reports from automated vulnerability scanners.

BOUNTIES:
All bounties are awarded at the discretion of the BitDegree Bug Rewards Team, based on the severity of the reported vulnerability. When an award is made, the bounty starts at Fifty Dollars ($50.00). Only one (1) bounty will be awarded per security bug. The awards will be made to the first researcher to responsibly disclose a particular bug.

Investigating and Reporting:

The security researcher submitting a vulnerability must thoroughly vet and confirm the vulnerability prior to submission. All submissions must include the following:

Steps to reproduce the vulnerability; and
A clear description of any accounts used in your report and any relationships between them.
To report a vulnerability, please send an email to security@bitdegree.org.

SUGGESTIONS FOR GOOD REPORTS:
The more detailed your steps for reproducing the bug, the better. This should include any pages that you visited, user IDs, links clicked, etc.
Videos and images are always useful, but are even more useful if accompanied by a description.
Exploit code that consistently works can allow us to verify your vulnerability more quickly.

CONFIDENTIALITY:
Any information that you collect about BitDegree, BitDegree employees, or BitDegree customers (“Confidential Information”) through the Bug Rewards Program must be kept confidential and may only be used in connection with the Program. You may disclose vulnerabilities only after proper remediation has occurred and you may not disclose Confidential Information without BitDegree’s prior written consent. Any disclosure of Confidential Information outside of this requirement will result in immediate removal from the Program.

LEGAL:
By participating in BitDegree’s Bug Rewards Program, you acknowledge that you have read and agree to BitDegree’s Universal Terms Of Service Agreement and Privacy Policy. Your testing must not violate any law, disrupt services, or compromise any data that is not your own. You are solely responsible for any applicable taxes or withholdings arising from or related to your participation in the BitDegree Bug Rewards Program, including any rewards that are paid. BitDegree may use a third-party service provider to manage its Bug Rewards Program. If so, the provider’s terms and conditions shall apply. The decision as to whether or not to pay a reward is entirely at the discretion of BitDegree. This is a discretionary rewards program. The program may be canceled at any time.

This policy crawled by Onyphe on the 2020-06-12 is sorted as securitytxt.

FireBounty © 2015-2024

Legal notices | Privacy policy