Banner object (1)

Hack and Take the Cash !

844 bounties in database
  Back Link to program      
28/08/2018
BitMEX logo
Thanks
Gift
Hall of Fame
Reward

Reward

50 $ 

BitMEX

BitMEX is a Bitcoin P2P trading platform offering fixed-date contracts on crypto-coins and fiat markets. BitMEX is the leader in Bitcoin trading by volume.

Our founders have a combined 40+ years of experience in the financial services industry.

We have a Testnet environment at https://testnet.bitmex.com __. If you believe a reproduction could potentially harm service of the platform, please do a reproduction on Testnet.

Disclosure Policy

  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
  • Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit, written permission of the account holder that you can provide to BitMEX.

Program Rules

  • Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.
  • Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
  • When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).
  • Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.

Exclusions

While researching, we'd like to ask you to refrain from engaging in or reporting:

  • Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
  • DDoS protection bypasses (we don't use CloudFlare)
  • Social engineering (including phishing) of BitMEX staff or contractors.
  • Any physical attempts against BitMEX property or data centers.
  • Bugs in non-standard browsers or browsers not supported by BitMEX.
  • Clickjacking on pages with no sensitive actions.
  • Unauthenticated/logout/login CSRF.
  • Attacks requiring MITM or physical access to a user's device.
  • Previously known vulnerable libraries without a working Proof of Concept.
  • Comma Separated Values (CSV) injection without demonstrating a vulnerability.
  • Missing best practices in SSL/TLS configuration.
  • Missing best practices without a working Proof of Concept.
  • Network disruption of service (DoS) attacks (i.e. connection floods, HTTP GET floods, etc).
    • App layer DoS testing is permissible as long as the testing is not load based and, as with the rest of the bug bounty program, only test on: https://testnet.bitmex.com __.
  • Path disclosure.
  • CSP Headers, X-Frame-Options, Content sniffing, HPKP, etc.
  • Content or text injection issues that are mitigated by CSP Headers or any other mitigations.
    • If you submit a report about a missing/incomplete header, please be absolutely sure you are correct that there is a legitimate problem. We receive a large number of bogus reports triggered by automated testing suites that do not consider the real-world use of the applications they are testing.
    • If you believe that one of the above is affecting a major browser in a negative way, come prepared with a working proof of concept. Reports without a proof of concept will be denied.

In Scope

Scope Type Scope Name
web_application

www.bitmex.com

web_application

*.bitmex.com

web_application

public.bitmex.com

web_application

https://www.bitmex.com/chatArchive __

Out of Scope

Scope Type Scope Name
web_application

analytics.bitmex.com

web_application

research.bitmex.com

web_application

blog.bitmex.com


This program crawled on the 2018-08-28 is sorted as bounty.

FireBounty © 2015-2019

Legal notices