52235 policies in database
Link to program      
2016-06-25
2020-05-06
FantasyTote logo
Thank
Gift
HOF
Reward

FantasyTote

Not taking new reports at this time.

No technology is perfect, and FantasyTote believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.

The logged in pages are currently under Http Basic Auth. hackerone is the username and password.

In order to test FantasyTote, your IP address must be coming from Austria Belgium Bulgaria Croatia Republic of Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Hungary Ireland Italy Latvia Lithuania Luxembourg Malta Netherlands Poland Portugal Romania Slovakia Slovenia Spain Sweden, United Kingdom ,Iceland Liechtenstein Norway . I cannot lift this restriction.

Disclosure Policy

  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
  • Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.

Exclusions

While researching, we'd like to ask you to refrain from:

  • Denial of service
  • Spamming
  • email/username enumeration
  • CSRF
  • HTTP Host header attacks
  • Brute forcing logins. An email gets send to account holder when this happens
  • When password/email changed, there is no email send. This has been mentioned in many cards. Alos that zz+s@gmail.com is the same as zz@gmail.com and all the issues around that. Fix coming.
  • Social engineering (including phishing) of FantasyTote staff or contractors
  • Any physical attempts against FantasyTote property or data centers
  • SPF record issues

Thank you for helping keep FantasyTote and our users safe!


This program crawled on the 2016-06-25 is sorted as bounty.

FireBounty © 2015-2024

Legal notices | Privacy policy