Bug Bounty Program by IEMLabs

Hunt for bugs in our system and get awarded with Hall of Fame’s and Exciting Rewards

About the program

Bug Bounty Program by IEMLabs is an initiative to encourage young talents in the field on Cyber Security to find out and report critical vulnerabilities. We invite all Ethical Hackers and Cyber Security Professionals to participate in our Bug Bounty Program and raise the standard of the Cyber Security industry. A researcher who successfully finds and report vulnerability will be awarded with “Hall of Fame Certificate” and “Exciting Goodies” from IEMLabs.

Scope Areas

In Scope

  • Remote Code Execution (RCE)
  • Web Shell Injection
  • Different types of Injections (SQLi
  • XSS
  • XXE
  • OS command
  • LDAP etc.)
  • Security Misconfiguration
  • Sensitive Data Exposure
  • Components with Known Vulnerabilities
  • Authentication bypass
  • Insecure direct object references

Out of Scope

  • Reflected Cross Site Scripting (Self Xss)
  • Descriptive error messages (e.g. stack traces application or server errors)
  • Misconfigured or lack of SPF records
  • Out of date software versions
  • Content Spoofing
  • Vulnerabilities that are limited to unsupported browsers will not be accepted. Exploit must work at least on > IE 8
  • .htaccess downloadable file without a real security misconfiguration that can have security impact Login page or one of our websites over HTTP
  • Clickjacking or any issue exploitable through clickjacking Vulnerabilities in our 3rd party partners source code on which we don’t have any control regarding the fix. This vulnerability should be directly reported to the 3rd party host (e.g. Hubspot)
  • Lack of Secure and HTTP Only flags
  • Weak SSL related issues
  • Username / Email enumeration
  • Cross Origin Resource Sharing (CORS) issues without a working Proof of Concept (POC)
  • Denial of Services (DOS)
  • Social Engineering Attacks
  • Cross Site Request Forgery (CSRF) in Contact form
  • Parameter Tampering in Payment Gateway

Submission Form

    Responsible security disclosure

    Abdessamad Lahlali – January, 2021

    Foysal Ahmed Fahim – February, 2021

    Get in Touch To get Free Demo

    We are available 24 * 7, Contact Us and Avail Exciting Discount Offers​

      WhatsApp Now