Infosec Institute

Open Bug Bounty mentioned in the
Top 6 Bug Bounty programs of
2022 by the InfoSec Institute

The Hacker News

Open Bug Bounty named among the
Top 5 Bug Bounty programs of 2021
by The Hacker News

Platform update: please use our new authentication mechanism to securely use the Open Bug Bounty Platform.
For security researchers
Report a Vulnerability
Submit, help fixing, get kudos.
For website owners
Start a Bug Bounty
Run your bounty program for free.
1,703,071 coordinated disclosures
1,356,501 fixed vulnerabilities
1,975 bug bounty programs, 3,891 websites
45,710 researchers, 1,643 honor badges

wall26 Bug Bounty Program

wall26 runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of wall26

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between wall26 and researchers.

Bug bounty program allow private and public submissions.

Bug Bounty Scope

The following websites are within the scope of the program:

*.wall26.com

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

Detail of the vulnerability

Testing Requirements:

POC required

Possible Awards:

Free product of our website.

Special Notes:

Thank you.

Other Submissions Handling

Website owner want to receive information about other vulnerabilities

Notifications:

[email protected]

General Requirements:

Detail of the vulnerability

Testing Requirements:

POC required

Possible Awards:

Free product of our website.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  Information How quickly researchers get responses to their submissions.
Remediation Time  Information How quickly reported submissions are fixed.
Cooperation and Respect  Information How fairly and respectfully researchers are being treated.

Researcher's comments

narasimhareddy5x5     17 March, 2021
Guys check your inbox response please :)
Manojkhd     20 August, 2020
    Manojkhd:
can you provide email verification for bug submission.
ChampionLeake     17 August, 2020
    ChampionLeake:
It was a pleasure working with the Wall26 staff.
Very communicative and very friendly.

  Latest Patched

 18.03.2024 agustiniano.edu.ar
 18.03.2024 armfox.am
 18.03.2024 delaur.am
 18.03.2024 money.udn.com
 17.03.2024 vtc.gov.tw
 17.03.2024 angra.rj.gov.br
 17.03.2024 sporthotel.am

  Latest Blog Posts

04.12.2023 by BAx99x
Unmasking the Power of Cross-Site Scripting (XSS): Types, Exploitation, Detection, and Tools
04.12.2023 by a13h1_
$1120: ATO Bug in Twitter’s
04.12.2023 by ClumsyLulz
How I found a Zero Day in W3 Schools
04.12.2023 by 24bkdoor
Hack the Web like a Pirate: Identifying Vulnerabilities with Style
04.12.2023 by 24bkdoor
Navigating the Bounty Seas with Open Bug Bounty

  Recent Recommendations

    16 March, 2024
    TorutheRedFox:
Thanks for the help with the XSS vulnerability. It was a quick fix.
    12 March, 2024
    fsousa:
Pooja found an XSS vulnerability in one of our websites and ethically reported it to us, providing all the information required for us to fix the site.
All the communication was so fast, almost real time!
We thank you very much for the time and knowledge shared with us!
    7 March, 2024
    ramram:
Reported an XSS vulnerability in our website.
    7 March, 2024
    jasongiss:
Thank you for your responsible and helpful disclosure.

We really appreciated that you followed up shortly afterwards and suggested a better implementation of our fix.

I'm very impressed with your approach - thank you!
    27 February, 2024
    GTCoSWeb:
Dipu1a helped notify us of a possible link exposure so we could remedy it quickly to avoid any issues.