Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 419,924 coordinated disclosures
228,381 fixed vulnerabilities
567 bug bounties with 1107 websites
11,361 researchers, 932 honor badges

loswebos.de GmbH Bug Bounty Program

loswebos.de GmbH runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of loswebos.de GmbH

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between loswebos.de GmbH and researchers.

Bug bounty program allow all submissions.

Bug Bounty Scope

The following websites are within the scope of the program:

loswebos.de

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

You can exploit the vulnerability for demonstration purpose, but this should not lead to service outages as well as the manipulation or loss of data. The purpose of the demonstration should show the full attack vector and should not cause any damage.

Do not share gathered information with third parties.

Please make sure to provide enough information so that we can reproduce the issue. A short description including a problem description and the URL of the affected system should be sufficient.

Testing Requirements:

Excludes:

- Physical security
- Social engineering
- Distributed Denial of Service (DDoS) attacks
- Spam & Phishing
- Exploiting vulnerabilities on systems which are dedicated to our customers

Possible Awards:

At the moment there are no general rewards, but this might change in the near future. Of course, rewards are not completely excluded.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

    12 August, 2019
    SecuNinja:
Responsive and friendly :)

  Latest Patched

 21.08.2019 metacritic.com
 21.08.2019 manaus.am.gov.br
 21.08.2019 pikdo.com
 20.08.2019 milb.com
 20.08.2019 dealabs.com
 20.08.2019 jobbkk.com
 20.08.2019 wine-searcher.com
 20.08.2019 beforward.jp
 20.08.2019 dartmouth.edu
 20.08.2019 funda.nl

  Latest Blog Posts

19.08.2019 by ismailtsdln
IBM - Cross site Scripting [XSS]
15.08.2019 by thevivekkryadav
HOW I WAS BYPASSED CLOUDFLARE WAF
13.08.2019 by Renzi25031469
XSSCon - XSS Tool @Kitploit
13.08.2019 by Cur1S3
I Found a multiple xss on https://clickmeeting.com
13.08.2019 by ZIKADS
xss at anghami.com

  Recent Recommendations

    21 August, 2019
     SelectLine_GmbH:
Thank you, Rooghz, for pointing out a vulnerability on one of our websites.
    20 August, 2019
     runlevelone:
Thank you for the reported vulnerability! I thought I had those XSS pitfalls covered, but aparently not.
    20 August, 2019
     fukubacchi:
Thanks for reporting the issue and the vulnerability details!!!
    19 August, 2019
     maxiorel:
Thanks for reporting the problem and the vulnerability details.
    18 August, 2019
     darshilsabhaya:
thanks sir