Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 450,227 coordinated disclosures
241,175 fixed vulnerabilities
598 bug bounties with 1217 websites
12,195 researchers, 959 honor badges

posao Bug Bounty Program

posao runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of posao

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between posao and researchers.

Bug bounty program allow private submissions only.

Bug Bounty Scope

The following websites are within the scope of the program:

posao.hr

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

Any potential website problems you deem worthy reporting.

Testing Requirements:

No special requirements.

Possible Awards:

[email protected]

Special Notes:

Any potential website problems you deem worthy reporting just let us know. Thank you.

Other Submissions Handling

Website owner want to receive information about other vulnerabilities

Notifications:

[email protected]

PGP Key:

Show key

--------------------

General Requirements:

Any potential website problems you deem worthy reporting just let us know. Thank you.

Testing Requirements:

Any potential website problems you deem worthy reporting just let us know. Thank you.

Possible Awards:

--------------------

Special Notes:

Any potential website problems you deem worthy reporting just let us know. Thank you.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

    20 September, 2019
    ssshah2131:
They said they are open for discussion and now not replying
    17 September, 2019
    gluttony:
Vulnerability with cvss of over 8 is minor bugs these guys. They say they are open for discussion.

  Latest Patched

 13.10.2019 fancourier.ro
 13.10.2019 interempresas.net
 13.10.2019 allbeauty.com
 13.10.2019 123test.com
 13.10.2019 autocosmos.com.mx
 13.10.2019 vogue.co.jp
 13.10.2019 au.ru
 13.10.2019 ohio.edu
 12.10.2019 bolha.com
 12.10.2019 ecu.edu.au

  Latest Blog Posts

01.10.2019 by Renzi25031469
#Security 100%
18.09.2019 by Leon
SSRF | Reading Local Files from DownNotifier server
13.09.2019 by drok3r
Collection of information | Google Hacking and Dorks basic
09.09.2019 by DakkarKey
New and Powerful XSS scan tool - XSpear
05.09.2019 by MiguelSantareno
Wordpress basic auditing

  Recent Recommendations

    11 October, 2019
     SimianE:
A comprehensive report helped me quickly patch a vulnerability on a recently deployed client system. I very much appreciate you taking the time to report with a reproducible test case. Many thanks.
    10 October, 2019
     BountyNeuvoo:
Dear,

Thank you for participating in our responsible disclosure program.

You helped us to solve a security vulnerability by informing us directly and delivering comprehensible examples.

We greatly appreciate your assistance in helping us maintain the security of our services.

Best regards
    10 October, 2019
     jshrc:
Nicolas was quick to let us know what the vulnerabilities were on our site. Thanks again!
    10 October, 2019
     ziduniwien:
Dear k0t,

The University of Vienna would like to thank you for your valuable contribution in finding a website security issue.

Your input is highly welcome and helps to raise the security level of our educational institution.

Servus and greetings from Vienna, Austria.
    10 October, 2019
     tschipie:
Thank you very much for finding and evaluating a vulnerability on our website. Very professional and detailed communication.