Report Security Issues

Reporting Security Issues

If you discover a security vulnerability on Shopitfree.com, we encourage you to contact us immediately. We will review all valid vulnerability reports and make every effort to resolve the issue quickly. Before submitting a report, please review this document, including the core principles, the rewards program, reward guidelines, and what should not be reported.

Core Principles

If you adhere to the guidelines below when reporting security issues to Shopitfree.com, we will not initiate legal action or law enforcement investigations against you. We require that:
1. You allow us a reasonable amount of time to review and resolve the reported issue before publicly disclosing any information about the report or sharing it with others.

2. You do not interact with private accounts (including modifying or accessing data from such accounts) unless the account owner has consented to those actions.

3. You make a good-faith effort to avoid violating privacy or causing disruption to others, including (but not limited to) data destruction and the disruption or degradation of our services.
4. You do not exploit the discovered vulnerability for any reason. (This includes demonstrating additional risks, such as attempting to compromise sensitive company data or seeking out other issues.)
5. You do not violate any other applicable laws or regulations.

REWARDS PROGRAM

We recognize and reward security researchers who help us protect our users by reporting vulnerabilities in our services. Rewards for such reports are determined entirely by Shopitfree.com, based on risk, impact, and other factors. To qualify for a reward, you must meet the following requirements:
1. Adhere to our core principles (see above).

2. Report a security bug: i.e., identify a vulnerability in our service or infrastructure that poses a security or privacy risk. (Note that Shopitfree.com makes the final determination regarding the risk level of an issue, and many bugs do not constitute security issues.)
3. Submit your report via email to our support team. Please do not contact staff members directly.
4. If you inadvertently cause a privacy breach or disruption (such as accessing account data, service configurations, or other confidential information) while investigating an issue, please clearly state this in your report.

5. We investigate and respond to all valid reports. However, due to the high volume of reports received, we prioritize assessments based on risk and other factors, and it may take some time before you receive a response.

6. We reserve the right to publish the reports.

REWARDS

Our rewards are based on the impact of the vulnerability. We will update the program periodically based on feedback, so please let us know if there are any areas of the program you think we could improve.

1. Please provide a detailed report with reproducible steps. If the report lacks sufficient detail to reproduce the issue, it will not qualify for a reward.

2. In the event of duplicate reports, we will award the first report that we are able to fully reproduce. 3. Multiple vulnerabilities stemming from a single root cause will be awarded a single bounty.
4. We determine bounty amounts based on several factors, including (but not limited to) impact, exploitability, and report quality. Specific bounty amounts are listed below.

5. The amounts below represent the maximum we will pay for each tier. We aim for fairness, and all bounty decisions are at our discretion.

Critical Vulnerabilities ($200):

Vulnerabilities that allow for privilege escalation on the platform—from an unprivileged user to an administrator—or enable remote code execution, financial theft, etc. Examples:

• Remote Code Execution
• Remote Command/Shell Execution
• Vertical Authentication Bypass
• SQL Injection leading to targeted data leakage
• Full account access

High-Severity Vulnerabilities ($100):

Vulnerabilities affecting the security of the platform, including the processes it supports. Examples:

• Horizontal Authentication Bypass
• Disclosure of sensitive company information
• Stored XSS affecting other users
• Local File Inclusion
• Insecure authentication cookie handling

Medium-Severity Vulnerabilities ($50):

Vulnerabilities affecting multiple users that require little to no user interaction to trigger. Examples:

• Common logic design flaws and business process defects
• Insecure Direct Object Reference (IDOR)

Low-Severity Vulnerabilities:

Issues affecting a single user that require significant interaction or specific prerequisites (e.g., MITM) to trigger. Examples:

• Open Redirect
• Reflected XSS
• Low-sensitivity information leakage

Client Contact:

Trade name: Shopitfree.com

Phone number: +84941349830

Email: admin@shopitfree.com

Physical address: RM 602, 6/F, KAI YUE COMM BUILDING, NO.2C, ARGYLE STREET, MONGKOK KOWLOON, HONG KONG