HostGator

  • Points – $4,500 per vulnerability
  • Safe harbor

Program stats

  • Vulnerabilities rewarded 23
  • Validation within 25 days 75% of submissions are accepted or rejected within 25 days

Latest hall of famers

Recently joined this program

Disclosure

Please note: This program does not allow disclosure. You may not release information about vulnerabilities found in this program to the public.

HostGator invites you to test and help secure our primary publicly facing assets - focusing on our main web application. We appreciate your efforts and hard work in making the internet (and HostGator) more secure, and look forward to working with the researcher community to create a meaningful and successful bug bounty program. Good luck and happy hunting!


Ratings:

For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.


Discovering Security Vulnerabilities

We encourage responsible security research on the Endurance services and products. We allow you to conduct vulnerability research and testing on the Endurance services and products to which you have authorized access. In no event shall your research and testing involve, without limitation:

  • Accessing, or attempting to access, accounts or data that do not belong to you or your authorized users,
  • Any attempt to download, modify, or destroy any data,
  • Executing, or attempting to execute, a denial of service attack,
  • Sending, or attempting to send, unsolicited or unauthorized email, spam or other forms of unsolicited messages,
  • Testing third party websites, applications or services that integrate with any Endurance services,
  • Posting, transmitting, uploading, linking to, sending or storing malware, viruses or similar harmful software, or otherwise attempting to interrupt or degrade the Endurance services.
  • Any activity that violates any applicable law.

Report Formatting

In the Description of a Vulnerability Report, please format the replication process as an Ordered List. Valid reports, formatted the following way, will be prioritized and accepted faster by Newfold Digital:

Steps To Reproduce: (Add details for how we can reproduce the issue)

  1. [add step 1]
  2. [add step 2]
  3. [add step 3]...

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.