انتقل إلى المحتوى

برنامج الإفصاح

لقيت ثغرة؟
قل لنا أولًا.

فريق الأمن وحده يقرأ بلاغك. نرد عليك خلال ٣ أيام، ونبقيك على اطلاع حتى نُصلحها.

داخل النطاق
pay.dokan.sa, tip.dokan.sa, metrics.dokan.sa, usr.gg, manage.usr.gg, rmz.gg, app.rmz.gg, front.rmz.gg, creators.sa, management.creators.sa, one.dokan.sa
المكافآت
من ٢٥ دولار إلى ٧٬٥٠٠ دولار، حسب الخطورة
  • حرجة٣٬٠٠٠ دولار–٧٬٥٠٠ دولار
  • عالية١٬٠٠٠ دولار–٢٬٥٠٠ دولار
  • متوسطة٣٠٠ دولار–١٬٠٠٠ دولار
  • منخفضة٢٥ دولار–٣٠٠ دولار
أول رد
عادةً خلال ساعة هذا الربع

حماية قانونية: إذا تصرّفت بحسن نية والتزمت بهذه السياسة، لن نتخذ ضدك أي إجراء قانوني.

Submission Guidelines Provide detailed steps to reproduce Include proof of concept Do not access user data DO NOT SUBMIT AUTOMATED REPORTS / AI GENERATED REPORTS Terms of Service 1. Introduction By participating in Dokan’s Bug Bounty Program (“Program”), you agree to these Terms & Conditions. The Program is designed to recognize and reward security researchers who identify and responsibly disclose vulnerabilities in Dokan’s websites and products. 2. Eligibility To participate, you must meet all of the following: Be at least 16 years old (minors must obtain parental/legal guardian consent). Not be a current or former employee of Dokan or its affiliates, nor an immediate family member of such an employee. Not reside in or submit reports from any country subject to U.S. export sanctions or other trade restrictions, and not be an embargoed or restricted person. Comply with all applicable local, state, and national laws. 3. Rewards Valid vulnerability reports are reviewed and, if accepted, rewarded within 30 days whenever possible. Bounty amounts are determined in accordance with CVSS 3.1 base scores (see NVD CVSS 3.1 Calculator). Dokan reserves discretion to award fixed or case-by-case bounties for vulnerabilities that do not neatly fit CVSS scoring. 4. Authorized Activities (“Rules”) Testing conducted strictly under these Terms is authorized, and Dokan will not pursue legal action against compliant researchers. If a third party threatens legal action for activity performed in compliance with these Terms, Dokan will confirm your compliance to that party. Any noncompliant activity may result in legal action by Dokan. 5. Program Requirements (“The DOs”) When participating, you must: Follow these Terms at all times. Respect user privacy; do not intentionally access or destroy personal data. Communicate courteously and respond promptly to researcher-team inquiries. Test only on assets in scope, using your own test accounts. Avoid negative impact on customers or services; pause tests if unsure and request further authorization. 6. Prohibited Activities (“The DO NOTs”) You must not: Leave systems more vulnerable than found. Perform brute-force attacks or credential guessing. Conduct denial-of-service (DoS/DDoS) attacks. Upload shells or backdoors. Publicly disclose vulnerabilities before Dokan’s written consent. Engage in social engineering targeting Dokan staff or customers. Extract or exfiltrate data you do not own or have explicit permission to access. Change passwords on accounts you do not own. Disrupt services or violate user privacy. Access or interact with accounts not owned by you. 7. Out of Scope The following are not eligible for bounty rewards: Physical attacks or social engineering (e.g., phishing Dokan employees). Push-notification/SMS/email abuse without content modification. Unauthorized takeovers of Dokan-related social media pages. Trivial or negligible impact reports. Unvalidated automated scan findings without proof-of-concept. Open-redirects without chaining. SSL/TLS scan outputs alone, or port enumeration without proof-of-concept. Best-practice recommendations or theoretical/speculative issues. Rate-limiting, dangling IPs, protocol mismatches, CSV injection. Self-XSS or console-only JavaScript injection. Missing flags on non-authentication cookies. Browser-version-specific issues affecting only outdated clients. Any vulnerability requiring physical access to a user’s device. 8. Reporting Process To submit a report: Prepare a clear, concise proof-of-concept and reproduction steps. Email your submission to [email protected]. Include: Full name and contact email Target (e.g., usr.gg, rmz.gg, tip.dokan.sa, pay.dokan.sa, or other) Severity estimate (Very Low, Low, Medium, High, Very High) Detailed description and steps to reproduce Dokan will acknowledge receipt, review your findings, and typically respond with questions or reward determination within 30 days. 9. Changes to Terms Dokan reserves the right to modify these Terms at any time. Continued participation after changes constitutes acceptance of the amended Terms. 10. Legal & Liability By participating, you understand and agree that: Dokan makes no guarantees regarding reward payment timelines or amounts. All decisions regarding program scope, eligibility, and payments are at Dokan’s sole discretion. Your sole remedy for any dispute arising under these Terms is limited to participation in the Program as described herein. Thank you for helping us secure Dokan and protect our users. Please direct any questions to [email protected].

الأصل المتأثر

وش مدى خطورتها برأيك؟اختياري

وش مدى خطورتها برأيك؟

صور PNG أو ملفات PDF أو سجلات طلبات بصيغة .txt، حتى ١٠ ميجابايت لكل ملف. احذف منها بيانات الآخرين.

نرسل لك التحديثات عليه، ولا يظهر للعامة أبدًا.

اختياري. اتركه فارغًا لو تبي تبقى مجهولًا.

يصلك رابط متابعة على بريدك، وتصلك الردود هناك أيضًا.