Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 421,977 coordinated disclosures
228,919 fixed vulnerabilities
571 bug bounties with 1111 websites
11,425 researchers, 932 honor badges

Boros Bug Bounty Program

Boros runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of Boros

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between Boros and researchers.

Bug bounty program allow private submissions only.

Bug Bounty Scope

The following websites are within the scope of the program:

*.gsmblog.com
*.officeshoescee.com
*.officeshoes.ws
*.officeshoes.cz
*.legend.rs
*.hocuto.rs
*.pokloni.com
*.officeshoes.hr
*.officeshoes.pl
*.officeshoes.ro
*.officeshoes.ba
*.officeshoes.me
*.officeshoesonline.sk
*.officeshoes.rs
*.officeshoes.hu

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

no special requirements.
if you find intrusive or data leak problem please contact me directly

Testing Requirements:

if possible provide us with full test scenario how to reproduce the issue

Possible Awards:

For confirmed problems recommendation on your profile and hall of fame.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

No comments so far.

  Latest Patched

 24.08.2019 animego.to
 24.08.2019 jrailpass.com
 24.08.2019 meteoam.it
 24.08.2019 mejorenvo.org
 23.08.2019 customs.gov.ng
 23.08.2019 canon.co.uk
 23.08.2019 cvent.com
 22.08.2019 cybrary.it
 22.08.2019 ohio.edu
 22.08.2019 vatgia.com

  Latest Blog Posts

19.08.2019 by ismailtsdln
IBM - Cross site Scripting [XSS]
15.08.2019 by thevivekkryadav
HOW I WAS BYPASSED CLOUDFLARE WAF
13.08.2019 by Renzi25031469
XSSCon - XSS Tool @Kitploit
13.08.2019 by Cur1S3
I Found a multiple xss on https://clickmeeting.com
13.08.2019 by ZIKADS
xss at anghami.com

  Recent Recommendations

    23 August, 2019
     MarkJasonRAng1:
tnx for the help
    22 August, 2019
     trash803:
Helpfully reported site vulnerability. Thanks.
    22 August, 2019
     SelectLine_GmbH:
Thanks for pointing out a vulnerability on one of our websites. And for the professional support.
    22 August, 2019
     Untanux:
Thank you for the report! We appreciate it.
    21 August, 2019
     aaccomazzi:
One more XSS bug discovered and patched thanks to Gh05tPT. Much appreciated!