Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,704,659 coordinated disclosures
1,383,224 fixed vulnerabilities
1,991 bug bounty programs, 3,919 websites
47,004 researchers, 1,651 honor badges

Jakub Boucek, Czech Republic Bug Bounty Program

Jakub Boucek, Czech Republic runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of Jakub Boucek, Czech Republic

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between Jakub Boucek, Czech Republic and researchers.

Bug bounty program allow private and public submissions.

Bug Bounty Scope

The following websites are within the scope of the program:

*.koldasoft.cz
*.kolarikova.cz
*.jiri-kolarik.cz
*.bouckova.cz
*.kolarik.cz
*.tak-jim-to-rekni.cz
*.kolarikovi.cz
*.kbs-praha.cz
*.ikofein.cz
*.ion.cz
jakub-boucek.cz

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

You are not allowed to make intensive automated testing of websites – it means rule violation.

Testing Requirements:

- No automated mass testing, I prefer bug searched directly with smart person – i have Kali linux too!
- Check if website have secutiry.txt and follow instruction to right reporting.

Possible Awards:

I am person developer, lot of my project was hobby only – I'm happy to cooperate and diskute with you, I'll make you famous, but please don't want money.

Special Notes:

I am persnon, not company. My work is my hobby, security is my obsession. Is very important to me have own web secured. But I dont't accept when you make huge mass automated exploit testing to my services without previous approval!!! That's does ton look like a fair deal.

Other Submissions Handling

Website owner want to receive information about other vulnerabilities

Notifications:

Please contact me on my e-mail: [email protected]
Please follow contacts: https://www.jakub-boucek.cz/.well-known/security.txt

PGP Key:

Show key

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBFMQss4BEADbDBDuSFDsdvih5Gb6Gphhl1xJ7H8Mo86XMcruZKCgfBWCVDiX
64WWV1aoH5SoGpDIY1AP9s3GHlgRpxvQ43BpWJRG8aq9MbqOr5yklEFJ2PCoCN2m
+GJ4nZ+XFRJIBX0nRwA6zNkZfmyE64Ova5NBKrZvffoF9ba/2HWFFyTeitq+GcHn
BZPZg2FAo4D49NE8jd8CR/KZwmNQNlpGw6ihdeJ1zxGX2QVBcKLtZsZY81RMtbqr
bi63Aw/7TQ+hqpQCEGCf9rklaRMhAwh52KYAe3fjPQDsk1sNUW9Y6LvZupQLyzwv
IEbTIEKpLiIgy7ZoPi1oLAjafMCwX++BwGJwONPIve7CsLT6e85NJgPbpLnmpy8Q
X72s5C8Sv8tytleN1Jh78O6wj+4aLeaCdD2zYZZ0kXSqJ729JQ2YW7lLseA72l9P
Lff3ZI4VPMl0il1GBvDYKUpH6Hk+ZHv4oMNn8XI5k0MRmrHzWbdKs4KEvHZpJpb5
RjaF4m3ZUJIb+iELMZqDqyLltMzTswox7LDZjCHRvrpmgTO0UdFVV09pmqypPF3g
iT3JrFQD8KCetX6yzVwJ6whu5baDxCGuF7P2dYCEJQZXnHcCBkycXm61vyGyY27a
DvX7V3OtvhO7rKmve5WbUE/R8PYCiV3HpVkcEr9bHLJoRMoXNZ/ymW1PTQARAQAB
tCJKYWt1YiBCb3XEjWVrIDxwYW5AamFrdWJib3VjZWsuY3o+iQJXBBMBCgBBAhsD
BQsJCAcDBRUKCQgLBRYCAwEAAh4BAheAAhkBFiEE3AvGWgf9l+MheVL2Il/cnAv6
onMFAlp74gsFCRCgaT0ACgkQIl/cnAv6onNFghAAoMeOrSHUjNyYDZGfcoKoeZ46
hk8A0AS3ZCndSXc+Y/B9fIjtcX4HktKfAoJnBllyrOBv3VGfweiB3qbNjvxf/k6t
VZBLEhNDRrHz8WY2220lR6AUGXcGcsXHUN8Fv5e/qeW6M20q+kGoZduOdIbGWtcl
j81CaOLY2h9vi/ySDSRedHM1hOi3ThgTYOWvwA1pcyTIL6zSMukQGm6GfvK4cUub
HTXnX+/8CiSewgCiHJzl3h2JFbN+6FgPN1d9qA1PGEZgcgTR+Cr9HGf1fgXXgosN
vRGPvQQ4jFSTscJJmSc7TWnBHcERB2dEbjxN8pZYPNQQPgxp2jtzLuoncDKr5efn
l264Nv9GVdkpI5MBbwKGXKYwjpZijnO1FhKMqSQP2AhE+Hl22zzdiXnmLhn1ft5d
fDOG3fmge41v35+XdcVCkdgcfnK13gaauuEOUCXuluYkyVp7mH/CXqTW1tCj4f1f
pDSfmIKsW/2KzQmdtUR8QqTR5dhj/8ypZSyTlNJMv6w1lgufDthzjiST1/XiRrTq
lrAlUz3N9iC1IvWA3LFGrOVT1hCGmzOv9Sv83On8otehnCXnewI+xnFBJAqhagNa
XNjMMNBecM62nNVNFEHbnBEVKQsIv4n+PjX3IVrERQEZjO0ar5q4qjjoQW34Rehh
p4deIGAIAbZN3cLKox+5Ag0EUxCyzgEQAMgHOaEjCK5kuLsVEo5uHnRv3IxEcToW
RT3l9sDrcxtoIfLscoHNkOBNpveaypK/QYG8P/a/yjfdEsRf4l8u6Vwz3iffyA+K
cVNhT/Bb/izw4qwGH7rzoFkg8CtPxWi8Po0+jRK4dICvg8k7bRqV2/kRjOPTsDSJ
LzLF6qWmDBNLGKhEV3Cl9Ahn0oca7h1aSzg9relMFTU9dm5lgeVKfd2tqC/LlzfX
9oTvIBxT+BOUnIGgGHKPnw1q3d4NMMQaFCXknwmvOT6ELrF9IvCqMz+TDHr6249x
50O966AncRsr5NYBSOwUyw2K9zsXgd4afBQT/R/JcFLhdGc/2AW2H3hY4hKzJHt+
V9alYSMVnOtUFHeTt0d/oj3t5JbifQvXX7/X6IMDcaTAdY5LXypSKy1K+XcFq+hm
XdcZj5/nKAbBMBlDFrgeAjeo/10VVqFFlHxgnOVAcNiqu38Cenu1sD+yxPlFYBQx
KLshFKeCy7m8QVmyz7GdtuvBzDj5JthHlXfL60G8VWHSLb11fNepg9lrQ/YL1XDh
AQxJpaOI8c3Pev4VPhPyL07BeYyYzvN6Py02rqxkidE5XFOLzNUJIRK90Z7NO5wN
D7m2GaYT+7Pk/ZL4x5gpVSmEyqGrPgcNJQx7mSq7wiziPFkRpGatUFjoNVYcL68K
ovip+t6yfAZ1ABEBAAGJAjwEGAEKACYCGwwWIQTcC8ZaB/2X4yF5UvYiX9ycC/qi
cwUCXb+CRAUJEKBAhgAKCRAiX9ycC/qic9EjD/9jvFCRzEIkMsqGW0LKnu9PAp5J
ArcTJ39wXqjjMZbYC2E/oypdjJLiWPNnGfj1m3LSypwupO7np6H9pf0sud8WMIQt
5ZghIDzEmSKeJigZWg/ymsxI0phm6bcD3Qtr7cpm8nlhRHxHnA2D3uGMob0sh3Tn
IVQ9x5szZOLkkCetVx9Zy/PbalO/sTv+KASCXB5Mzsgy0Cm/qoTigLv9D6VyIhz0
vjMM+WKYnTPrbwsgdDQeBMhc8lo2cNVpoTs7WwAiq8x0WNMK7qGDWo+dnk80bpep
VhWo5G8FwiEQndu3ahAKtFxtHx3sgsnlv3nuV9WMf68Kn2CeIqO8kPaH748SuX1e
2U1VCWqieL1yHLuFC5mKjsZQqKI5lO2aBUyhTFB9uxqxWidCJk3ahqFj/MBPG99F
6ZoMjil7fFl1E+i3kil5HmB02gr/YzUVmwtegXkNnexoFmfw0JDp9MOV2WQl86FC
tp/jc8UKL/8p7KS7KfQGyE3bbZqKn/ytQXJmgiRg6DnnHF7ZlVmUaq8crMNSD5ls
h/5jmNYQvIhQEvdjYGYKdN+quUNqAnBpUmmuedgiP/ScG5GQ7NooPocrSrKPyaVY
wOu1qJNEp0kAS28bhjJr0jgre9IdJqhm1mDg+5usRqrJwSDoHngUtf+tBp9TQ/Co
oRPDjJZWeammS6kPebkEDQRU6yqMEBAA7z424FOzRv+YC49/nRy+FB03ZdC5nnE3
rA6/kDZV+Srae1urKYzNUmU7qXEhF/E5qsvPn6CmKPSG40hp0hNXI9iwrMXnmTfg
1mY9Mdyg5wA+9+IpyDiI5BEnRo3kYBHdNEoGsCc3WGL5wnjfSMywJ92w644ocPWU
kiSbcVW9PKDW0cuyLPf3eJ/jVzrO883224McY8B6YRSt6QOgtipVhWAamkfgKb5D
NOXH1Z5GiCYwjnJwRceU4cKyr7rCbc2W7y2ITMf8jZLI5ObxQ/0jN3yUjIDvTsQf
SlujDC6wZeTQIKBH8lvQg1JjafLexSERoYSBofBv/FAEXXMcwFOZWDV4dAUqXgMj
ViuJJfjT+KGNOkqRk7+dR8/CFrnZoXOR/3fjdnraEFRljdIqN64zlnKz14UmbJ8r
LepomC2lga+GZObH1jPU0bqiXP6whYTkVI2qwj0hjFQi9Aoe595y7YWwzV4Nhtnk
5l+5zzaAko8ORK7C8jIOYf6cF/wsVKXfCFik0hceBGU9GbwTgxq1+Q0N5vSzclkb
o2DmWGk8IkyZgoAVhpaDnK8YzhUNW8S+8M1roemVThIF2icvwnzOd+FnoCqiEtKb
na98AodSu9YVmipn1sabVz/5RYJnOKCqJUJYUnpirMrqxGBLd17a1tEnXwF1QNZh
qBnMGLw61PMAAwUQAMIV4H04CwhCXlQq3srxJxVhiHWaoVNLWjWPHLpcKsjhQhMh
ITtJs5WDs+A7bNTyzDeFSUD/FFGP13yRVXpaxCst+LXqwpXP3pyJnjVXzhPc1ZEM
NL62tgm9mXFgYd3/F0ovfFehwZsrJTuT2+NQyi54YKboR1mPvxgxxhvDwPffEe4i
H4ZFKu7lACvzq99jsr5s+C2zuhdi5cRpHvh8DMt1MAlH+76UXYeky4iKqfruTWrt
cwoSdtkYrNH5A+vG5g24eE4SfqvdwtgleJnbzWFGSwsLIVEF0RvNgvcMFTzN2pfj
0SmuyBnd8Rop5WUJRQ0a8y+rTq58eXQjl8aG1B8d7gr4LmmEFkNZPfjQS1uYYpnt
PcYS3zWiEuzwl8jwAg/j5vZA1DDSDS83Mjiwl6PJloN3aIh3raIzAX0mPh8CMPzU
ynugR5/63fR4Dcn3ylRWxP8whlCj4vyt5yoIZ8y1TDy+6CY8WwB6j+ybPuNXdrnz
8bKDahyxRoQGN7HIxXL4C0y8gh2t4s3goVs4CnKm2h7H3Pco7MjrgUI2M7gxeqPx
bpC/c/j6zJ1VYBUbH8eC5nLtjS3Qh71cXuO2Fyf8ysycRHTwAEqlLOVMRbGekmKd
tzPTQuFfw0V9sJN62i2lrpEBnPD27ScEKZVQpkFlTQuOld8XtTeOC+zj0f7diQI8
BBgBCgAmAhsMFiEE3AvGWgf9l+MheVL2Il/cnAv6onMFAl2/giEFCQ7FyKUACgkQ
Il/cnAv6onMDsQ//Q97oSjYtNCJzz3XmvPptnRzdpn/0yynf+WC2RG+Yq14pvOXV
54299ZMBf9Z+G0TSROZIryycWlPEqtFOTcTymLR8jm8snJBEUW0r/Niwo8Fo3f49
lTQMCD1Ez/AhTQHQvDZTsshCoPmWKp9utGVsON6/oYCwc/TGPiC7jZq2kqcLABdb
7IU0RHo7T0o7OiuC2IVB2YbJTx+svmhzp8ch2AO/5HEAS4HwE/PD2CRD9mUTwdLh
1S1i66MIRiBM1POM5p6Ujq2HjRgZXZQQuUdBw3yy2YuHuMwOxpKU/z7eN5ZPWGZ9
mXesJP5eOHVQ3Ifvt/n6mLVbAdDWpYFlowhKYvCPEgafo3E/DWyYwh6GN+dLrEas
pY6mxWBmhG6MAX1VkxZ9S7GSUMDGB99336ic2rpjzB47vtWGufPj2V+Bcn1/jCLR
GeAR07l1ItZQR26RZwAACNXfsViuQIPz0JOBCPI7MFX7iQUxL6rJfgwfVOR9LqXF
jJ/LYUVtzMbCLz5CYaja0bCQxwNiBXWDS4RSE7vZjPG7mns0P5RKZNqobgIdi5c2
SCUIKRhNZ8mUZ2eO9syM/2o/WxKoVqmpx5Bx/yMeAWxuNZADcShatexLHEl/oxxY
R4dx3Rn7uNuWtXbIvt8opxHYUCdXeSTjAB1YwAmFXoMG882ZiMA9d5lInWa5Ay4E
VOsrHxEIAOAyJ5719ucSx3COWLOt5lWODiXM8x5oE7bwid6TD3aqkUwI4c0aYsDz
I4zwFvrmxwdCRdOiF1F4w2U+Ce8trzv9gST/xHQxZfu6RQGDgXAydTiBdSv/A5Nx
CR291nSvV4F4PSFUyuKailPcgHK3KsoegxNaWbwXFYEWfpyyV35cCuP1FoWRLqfa
HeQh5Fc0LPaNZzlZpYfLZ8+CSbLb9ZxmW0ZSY2DGo3v4Fam9nFoM3J7aUOz5KkNo
PxbwV+yDOi0eFKvzJNwpnGX2nCsjlG3dWEE6qt7Hl4CVqeWX+OT82uvszMv/r9zc
AjxKeNSd6ckI/yhU/bHuFOUjepFqwBcBAP+caZcE7v5T4OubIo94TB4gOiH9UuCB
CjW5/x62+UO9CADUhXZ0hSHbH6BczNI3FM1an/E72TJnH6imY53S4DSBQrmZGLdB
cFuAMjkLWG7cEO1OmT0USPWAkUGa8SFW8Si9Zd12nNpC2225oFXPSj/RviQRn6Sb
mnziTsYEZEvzXSyszAhFjq46lnZKMYSFYmD2IRqmn/y0ib9Ur0sSL3QA7ZfOWyqC
ALQrp4KxM8FsI1MBAUUtJHbHqhWxHb3umkNprkQJp8fB1D+j2PnYN3Oerc6gStGF
XNzVzwVcQGSigGgnQ+4gEonClOxWfmtD7b9H4SAdmJ1gtuuDGpOnRsoe70BCyTUB
27p+AfvgwMKELbXMNK6I1XzH884ICxjLnVtvCADYbYq2vXUfL8Em56uuhhyL0Jn0
ADXjj2mJ1EyWuu5q/EwbusIRPaGEccBS0O225eVJYBg9eI3Rf9H7Ucd+DMPJsSqX
HqmObvQPAmsixdqwz053iq0sGqygIYXQYcHbu3p8Mqdz/8bfbS+JX4xG64WPR4Jm
JXCBQBq0U7zbf2MpB+RIXWdDNXO9/dkgfAsAlg2TVCGyUR4yzRKWzMTY4NxaSxbB
PiUL4gNuqvqoVlqvMjQYhqvT2i6Tc8nrFGz57584dCWbmZN+BZSyWGFyv6i9e6w1
SlPbznvq+CsjhoViBMSCPvsxSYMhgEtHbVoE1t7zbCQYeDGROi7z1abs3E4WiQKc
BBgBCgAmAhsCFiEE3AvGWgf9l+MheVL2Il/cnAv6onMFAl2/ggQFCQ7Fx/QAal8g
BBkRCgAGBQJU6ysfAAoJEMjxt7hZW8bOE3QA/0sg/KBtCAs5wDU/ElyNYUQkiuug
4H7YYd3NWxsXfFoxAP4+XFf2/LUPPFXZ3iD8IN7Z/pA1JDJ+zQ3TBUbXBUZYnAkQ
Il/cnAv6onOd8A//aFK0oK21F9Ck10xQRUDZYDBPVCYN7nLoaOTKP3AfS4oxIyuI
hGXvRUgzyubG5bcqW+PbT8MJL05ZKUdglFWLbOoueXeqfF3RX6uPEIAceXzJ9KLS
BL4kWA+BMikCaC4q5Lqen1J+4xp54U4fwqzejNXqZ9JAyeeU1T7+lDaFdBaKLr8H
iidLItQ9ZJTPMYdIY77T1FSkMtEpzFhdexiMEb7juGXPFiBx2G+o0OYj0pESO2h/
astYOGVPMfIBEYRELsgBOol58kzDzs6s2CyBv9mz3GZVr1bl2RP51wTfA5uaYZ1N
sZC8De0jtl1th9RMU1X4l/7YRAriYzv40Lcx9oaQotvN1LIKZ8pSXAn6PD6qitF7
kc2CHOWa5dCxsjn852coeEVyp7Ng9hnK0f1WhMBz/hCnS27Q8Vr30RJqf0i7kYxO
aisHVG1VDynxrzhWb2sNG/dfCqEPV/vo5qHQB2yH3OWIFCLAUIEGoIgT6ixrGaRu
5kvxserPpF/2lrbjAJGv5mRJSYxR04vLIMex5H5KX3LkXQe21vw4Er/rZi/yOFZ2
dMfu8ZXT4fyN8Z+efkZ88Ea0hhpt+hbf2lkf6fiQLh49j4M+cJUzEsyt6YpLohJv
2jJBHDmhJlGUJeVYUP0RyM2TxtopztsvG68U0mUQw5gGQFoumrCx5t70/2s=
=BeTk
-----END PGP PUBLIC KEY BLOCK-----

General Requirements:

Any bugs, other vulnerability or orher missing security feature which that has the ability to interfere with system's or user's security.

Testing Requirements:

- No automated mass testing, I prefer bug searched directly with smart person – i have Kali linux too!
- Check if website have secutiry.txt and follow instruction to right reporting.

Possible Awards:

Hall of fame on my Acknowledgements: https://www.jakub-boucek.cz/.well-known/security-acknowledgements.txt

Special Notes:

Very thanks to gently & fair access.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  Information How quickly researchers get responses to their submissions.
Remediation Time  Information How quickly reported submissions are fixed.
Cooperation and Respect  Information How fairly and respectfully researchers are being treated.

Researcher's comments

No comments so far.

  Latest Patched

 25.04.2024 xaxim.sc.gov.br
 25.04.2024 lacerdopolis.sc.gov.br
 24.04.2024 tap.mk.gov.lv
 23.04.2024 data.aad.gov.au
 23.04.2024 bitporno.to
 23.04.2024 sys01.lib.hkbu.edu.hk
 23.04.2024 srvm.gov.za
 22.04.2024 stc.edu.hk
 22.04.2024 friv5online.com
 20.04.2024 brandonfowler.me

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    22 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!
    10 April, 2024
    Mars:
Hatim uncovered a XSS bug that we were able to quickly resolve. Thanks very much for your assistance and help.
    8 April, 2024
    Panthermedia:
Thanks to the support of Hatim Chabik, we were able to identify and solve an XSS bug.
    5 April, 2024
    pubpharm:
Pooja found a XSS vulnerability on our website and provided us with the needed Information for replication and fixing the issue. Which she verified afterwards.
We thank her for the reporting and assistance.
    2 April, 2024
    genoverband:
Thank you for your invaluable help in ensuring the security of our domain and its visitors!