Submit discovered vulnerabilities according to the program guidelines to the address below and receive cash rewards after validation by the security team:
1.
Respect the privacy of all Ramzito users. Absolutely avoid disclosure, alteration, theft, or destruction of any data.
2.
Perform all testing processes only with your own registered Ramzito account and mobile phone number.
3.
Before beginning your tests, check the scope section to ensure the domain is within the program limits. For questions, contact {supportEmail}.
4.
Avoid any testing activities that may disrupt Ramzito's core business operations or system availability.
5.
Vulnerabilities must be reported strictly within the defined scope.
6.
Each submission must contain only one distinct security vulnerability report.
7.
The primary standard for determining vulnerability severity is CVSS (Common Vulnerability Scoring System).
8.
Including the exact payload (code, scripts, etc.) used to discover the bug in your report is strictly mandatory.
9.
Submitted vulnerabilities must be fully reproducible and provable, with clear step-by-step instructions.
10.
Automated tool scans and direct scanner outputs without human verification are strictly prohibited.
11.
Do not disclose any vulnerability details to third parties without prior written consent from Ramzito. This includes social media, other entities, or the press.
12.
If you are reporting a data breach or leakage instead of a security vulnerability, specify the exact location of the data and keep details confidential.
13.
Upon submission, we will accept or reject the report within 1 business day. Validation and response will be provided within 10 business days. Valid reports will receive a severity level and cash reward, payable to your bank account or crypto address within 14 business days.
Server-Side Request Forgery (SSRF)
Information Disclosure
Improper Access Control
Cross-site Scripting (XSS)
Improper Authentication
SQL Injection
Privilege Escalation
Insecure Direct Object Reference (IDOR)
Social Engineering, Physical Attacks, Spamming, SMS Bombing, DDoS Attacks, Non-Critical Rate Limiting, Any Brute Force Attacks, Malware Distribution, Phishing Attempts, Insider Threats
Lack of SPF, DKIM, or DMARC implementation.
Vulnerabilities on third-party-hosted sites, unless they directly impact the main website or involve deprecated open-source libraries.
Automated tool or scanner outputs, AI-generated reports, or issues that aren't reproducible.
Publicly disclosed vulnerabilities in third-party libraries or technologies within 30 days of disclosure.
Vulnerabilities requiring improbable user interaction or affecting outdated or unpatched browsers, or those needing root or jailbreak on mobile devices.
TLS cipher suite offerings, suggestions on best practices, non-security-impacting UX issues, or self-XSS with no security impact.
Reports lacking detailed instructions or proof of concept, or those disclosed publicly before a comprehensive fix is issued.
CSRF-able actions that don't require authentication or a session, and user enumeration.