Security
We have long enjoyed a close relationship with the security research community. To honor all the cutting-edge external contributions that help us keep our users safe, we maintain a Vulnerability Reward Program for Cybernetics APP running continuously since November 2023.
In principle, any Cybernetics application subsidiary web service that handles reasonably sensitive user data is intended to be in scope. This includes virtually all the content in the following domains:
For further services and devices that are also in scope, see the rules for the following reward programs:
Any design or implementation issue that substantially affects the confidentiality or integrity of user data is likely to be in scope for the program. Common examples include: Cross-site scripting, Cross-site request forgery, Mixed-content scripts, Authentication or authorization flaws, Server-side code execution bugs. Note: In addition, significant abuse-related methodologies are also in scope for this program, if the reported attack scenario displays a design or implementation issue in a Cybernetics product that could lead to significant harm. An example of an abuse-related methodology would be a technique by which an attacker is able to abuse our API by exploiting a vulnerabilities that go undetected by our security systems.
Out of concern for the availability of our services to all users, please do not attempt to carry out DoS attacks, leverage black hat SEO techniques, spam people, or do other similarly questionable things. We also discourage the use of any vulnerability testing tools that automatically generate very significant volumes of traffic.
Rewards for qualifying bugs range from $100 to $2000. The following table outlines the usual rewards chosen for the most common classes of bugs. To read more about our approach to vulnerability rewards you can read our article here.
| Category | Examples | Applications that permit taking over a Cybernetics Account [1] | Other highly sensitive applications [2] | Normal Cybernetics applications | Non-integrated acquisitions and other sandboxed or lower priority applications [3] |
|---|---|---|---|---|---|
| Vulnerabilities giving direct access to app.cybernetics.fr servers | |||||
| Remote code execution | Command injection, deserialization bugs, sandbox escapes | $2000 | $2000 | $2000 | $100 - $500 |
| Unrestricted file system or database access | Unsandboxed XXE, SQL injection | $2000 | $2000 | $2000 | $100 - $2000 |
| Logic flaw bugs leaking or bypassing significant security controls | Direct object reference, remote user impersonation | $2000 | $1000 | $2000 | $250 |
| Vulnerabilities giving access to client or authenticated session of the logged-in victim | |||||
| Execute code on the client | Web: Cross-site scripting Mobile / Hardware: Code execution | $2000 | $2000 | $1200 | $100 |
| Other valid security vulnerabilities | Web: CSRF, Clickjacking Mobile / Hardware: Information leak, privilege escalation | $100 - $1800 | $100 - $1800 | $100 - $1800 | $100 |