iwantcoding.com
🔥 Daily 👥 Rooms 🏆 Top Log in Sign up

Bug Bounty

A bug bounty programme is a structured way to receive vulnerability reports from external researchers. The non-negotiables are: a public policy with safe-harbour language, a clear scope (what to test, what is off-limits), an SLA for triage, and a payout table tied to severity. Without these, you get noise and unhappy researchers.

A minimal bug bounty policy template

EXAMPLE
# Vulnerability Disclosure & Bug Bounty Policy

## Safe Harbour
We will not pursue legal action against researchers who:
- Stay within the scope listed below.
- Avoid privacy violations, destruction of data, and service disruption.
- Give us reasonable time to remediate before public disclosure.

## In Scope
- Production web app: https://app.example.com
- Public API: https://api.example.com/v1/*
- Marketing site: https://example.com

## Out of Scope
- Staging, sandbox, and *.dev.example.com hosts
- Third-party services (Stripe, Auth0, SendGrid) — report to them directly
- Social engineering of staff or customers
- Physical attacks on offices
- Denial-of-service, volumetric testing, or rate-limit bypass at scale

## How to Report
Email security@example.com with PGP key 0xABCD1234.
Include: steps to reproduce, impact, and any PoC code.
We acknowledge within 2 business days.

## Severity & Reward Bands (AUD)
| Severity  | Examples                                         | Reward       |
|-----------|--------------------------------------------------|--------------|
| Critical  | RCE, auth bypass to any account, mass PII export | $5,000-15,000 |
| High      | Stored XSS w/ auth, IDOR exposing other users    | $1,500-5,000  |
| Medium    | Reflected XSS, CSRF on sensitive action          | $500-1,500    |
| Low       | Self-XSS, missing headers, info disclosure       | $100-500      |

## Triage SLA
- Acknowledge: 2 business days
- Triage decision: 5 business days
- Fix critical: 14 days; high: 30 days; medium/low: 90 days

## Disclosure
Coordinated. We credit researchers in our hall of fame on resolution.

Why it matters

Scope discipline is what makes a programme sustainable. A vague "all of example.com" invites reports about marketing typos and DNS misconfigurations; a tight, named scope concentrates effort on assets you actually want pressure-tested.

Tip: Tweak the snippet with Try it Yourself », then sit the quiz at the bottom of the page.

Example

Example
// Start with a vulnerability-disclosure policy (security.txt).
// Scale up via HackerOne / Bugcrowd / Intigriti when ready.
Try it Yourself »

Discussion

Loading…