At OLX, we take security issues seriously. If you believe you've detected a vulnerability within our products we'd like to hear about it. We'll investigate all reports and do our best to fix these issues as soon as possible.
The scope of our program includes the following sites:
You can review OLX sites in the scope section. Android/iOS apps related to these sites are also included in the scope. Vulnerabilities need to be documented in a way that they can be reproduced. Send screen-shots, code, video to helps to understand it.
Other OLX products from different countries are not included in scope.
We're more than happy to publicly disclose your bug once it has been fixed by our developers.
Any activity that would disrupt, damage or adversely affect any third-party data or account is not allowed. Please do not mass create accounts to perform testing. Also do not perform brute force testing to determine whether rate limiting is in place for particular APIs or pieces of functionality.
The following are strictly prohibited:
This vulnerabilities are out of scope since we're currently aware of these vulnerabilities in some of our products and actively working on them.
Software version disclosure
HttpOnly and Secure cookie flags
At this time, we are not awarding bounties or cash rewards for reported vulnerabilities.
At OLX, we take security issues seriously. If you believe you've detected a vulnerability within our products we'd like to hear about it. We'll investigate all reports and do our best to fix these issues as soon as possible.
This program have been found on Hackerone on 2016-07-11.
FireBounty © 2015-2024