Bug bounty 2018

Until further notice, I offer the following rewards for the discovery of bugs in the Ancient Brain site.
  • € 30 for a minor bug.
  • € 100 for a major bug.
  • € 200 for a critical bug.
My decisions are final.

I have the funds. So go try and hack it!

I have paid out € 1,400 so far. Thanks to all who submitted bugs. Keep them coming! Find more!

Hacking ideas

Here are some ideas to test for bugs and exploits:


Do not cause damage

If you find an exploit that can cause damage:

If you actually cause damage, you will not be paid. Instead, report how you could cause damage, and collect your payment.


Do not report

I am aware of the following issues. Do not report them: I also know I have a simple registration/login/password-reset system. Do not bother reporting these issues:
  • Registration does not allow picking your own password at the start.
  • Change email does not validate new email, or inform the old email.
  • The "forgot/reset password" process is too simple.
  • Logout/in on one tab does not logout/in on all other tabs.
  • Change password / forgot password does not force logout on all devices.
  • CSRF token needed for login/logout
Do not bother reporting issues on these platforms:
  • IE
  • Windows Phone
  • Any platform that is discontinued.
  • Any browser that does not support HTML5.
Also: First come first served. Second report of same bug gets nothing.

Firewall blocks

Hacking attempts may trigger the site firewall (not my code) and it may give you blocks/timeouts if certain rules are triggered.
  • To check if your IP is blocked / given a timeout, or if something else is going on, try the site from another IP.
  • An actual bug might be if firewall rules are being triggered when they should not be, so you could report that.
  • When you attempt an exploit, it can be hard to tell if it got through and then generated an error, or if it never got through and the firewall blocked it. So you may report what looks like the former and then I look into it and discover it is only the latter.

Send reports

Send bug and exploit reports to:
bugs@ancientbrain.com

And you will (subject to my decision) get rewards as above.

Dr. Mark Humphrys
Ancient Brain Ltd
DCU Invent centre
Dublin City University
Glasnevin, Dublin 9, Ireland

Tel: (+353 1) 700-8059
Fax: (+353 1) 700-5442



The background is a program, showing the JavaScript graphics used on this site.
 
Font:

© Ancient Brain Ltd. All rights reserved.

Ancient Brain ™ is a trademark of Ancient Brain Ltd.

Beta      Bug bounty      Contact      Stats      The name      Terms and conditions