Zolo Blog

Categories

  • City Life
  • Coliving
  • Community
  • Corporate
  • Entertainment
  • Horror
  • Jobs and Education
  • Lifestyle
  • News
  • Personal Finance
  • Sports
  • Travel
  • Uncategorized
  • Zolo Scholar
  • Zolostays
  • Home
  • Explore Cities
  • Contact Us
Zolo Blog
Zolo Blog
  • Home
  • Jobs and Education
  • Lifestyle
    • City Life
  • News
  • Personal Finance
  • Sports
  • Coliving
  • Travel
  • Community

Zolo Security Bug Bounty Program

  • January 10, 2020
  • 1.1K views
  • 2 minute read
  • Zolo Admin
Total
0
Shares
0
0
0

Zolo engineers work hard to make our products safe for our customers. We invite reports from independent security researchers about possible security vulnerabilities with our products.

Guidelines for submitting the vulnerabilities

  • Don’t attempt to gain access to another user’s account or data.
  • Don’t perform any attack that could harm the reliability/integrity of our services or data.
  • DDoS/spam attacks are not allowed.
  • Don’t publicly disclose a bug before it has been fixed.
  • Never attempt non-technical attacks such as social engineering, phishing, or physical attacks against our employees, users, or infrastructure.
  • Please submit bugs with POC to email address  tech-security@zolostays.com

Eligibility for the reward

  • The security bug must be original and previously unreported.
  • You must not be an employee, contractor, or otherwise, have a business relationship with Zolo
  • We should be able to reproduce the bug.
  • It is entirely at our discretion to decide whether a bug is significant enough to be eligible for a reward.
  • Following vulnerabilities are eligible for a reward
    • Cross-Site Request Forgery (CSRF)
    • Cross-Site Scripting (XSS)
    • Code Executions
    • SQL injections
    • Server Side Request Forgery (SSRF)
    • Privilege Escalations
    • Authentication Bypasses
    • File inclusions (Local & Remote)
    • Protection Mechanism bypasses (CSRF bypass, etc.)
    • Leakage of sensitive data
    • Directory Traversal
    • Payment manipulation
    • Administration portals without an authentication mechanism
    • Open redirects which allow stealing tokens/secrets
  • Following vulnerabilities are not eligible for a reward
    • Clickjacking
    • Application stack traces (Path disclosures, etc.)
    • Self-type Cross Site Scripting / Self-XSS
    • Vulnerabilities that require Man in the Middle (MiTM) attacks
    • Denial of Service attacks
    • CSRF issues on actions with minimal impact
    • Cache Poisoning
    • Missing SPF records
    • Brute force attacks

Hall of Fame

  • Mohith Kalyan
  • Sudhanshu Chauhan
  • Tinu Tomy
  • Vishal Yadav
  • Mansouri Badis
  • Saikat Banerjee
  • Shahrukh Iqbal Mirza
  • Devender Rao
Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Community

Best restaurants in Indiranagar for a peaceful New Year’s Eve

  • December 23, 2019
  • Zolo Admin
View Post
Next Article
  • Community

Best Packers and Movers in Bangalore

  • January 14, 2020
  • Zolo Admin
View Post
You May Also Like
View Post
  • Community

What is The Price of Gents PG in Pune?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

Does PG in Pune provide food?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

How to get a girl’s Hostel in Pune?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

Is it easy to get PG in Pune?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

What is better in Pune PG or flat?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

Which is the Best Area for PG in Pune?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

Which PG is best in Pune?

  • December 6, 2023
  • Zolo Admin
View Post
  • Community

National Stress Awareness Day

  • November 2, 2023
  • Zolo Admin

Recent Posts

  • What is the cost of PG in Noida
  • What is the Cost of PG in Gurgaon?
  • How much does a PG in Mumbai cost?
  • HSR Layout Unveiled: A Comprehensive Guide
  • Top 10 Pubs and Clubs in Pune| New Year’s Eve Celebration

Recent Comments

No comments to show.
The Zolo Blog
Your Guide To Lifestyle

Input your search keywords and press Enter.