Third Party Index

Snapshot 40892

Document
Security advisories
URL
https://www.dailybot.com/programs/vulnerability-disclosure/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
93656 bytes
SHA-256 (raw)
94d74dcf1da58aa3b8e0772434f2ede2407469d65bcdac03437f21f4ec6afc9e
SHA-256 (normalized text)
59cc568c67af835d3c71f4f167c1dca8dba782150e017da4b6640ba809f95773

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to content
Dailybot Responsible Vulnerability Disclosure
Submit a Vulnerability
Responsible Vulnerability Disclosure
At Dailybot, we take privacy and security seriously. We welcome security researchers and members of the community who responsibly identify and disclose potential security vulnerabilities affecting Dailybot.
This vulnerability disclosure program provides a clear process for reporting security issues so our team can investigate and address them appropriately. We appreciate the time and effort of researchers who help us improve the security of Dailybot.
At the moment, we're only accepting reports made on the following subdomains: app.dailybot.com, api.dailybot.com, api.dailybot.co
How we approach security issues
Dailybot will not take legal action against users for disclosing vulnerabilities as instructed here.
Vulnerability reports will always be responded to as fast as possible—usually within 24 hours.
We will provide a full write-up of steps we've taken to resolve any issues you reported.
We greatly appreciate responsible vulnerability reports and the researchers who help us improve Dailybot's security. This is a voluntary vulnerability disclosure program and does not offer or guarantee monetary rewards or other compensation for submitted reports.
Program Rules
Only use and test on accounts and servers you directly own. Testing should never affect other users.
Testing should be limited to sites and services that Dailybot directly operates. We will not accept reports for third-party services or providers that integrate with Dailybot through our APIs.
Don't perform any actions that could harm the reliability or integrity of our services and data. Some examples of harmful activities that are not permitted under this program include: brute forcing, denial of service (DoS), spamming, timing attacks, etc.
Don't use scanners or automated tools to find vulnerabilities.
Don't try to test API Rate Limits neither make a high amount of requests under a short period of time.
No information about issues found should be publicly disclosed or shared until we've completed our investigation and resolution. After confirmation, you are free to document and publish any information about the issues you've found.
Out of Scope Vulnerabilities
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are generally considered out of scope (not an exhaustive list):
Account/E-mail enumeration
Attacks requiring MITM or physical access to a user's device
Brute force attacks
API Rate Limits
Clickjacking
Content spoofing and text injection
CSRF vulnerabilities
Denial of Service attacks
Email SPF, DKIM, and DMARC records
Invite enumeration
Missing HttpOnly/Secure cookie flags
Open CORS headers
Publicly accessible login panels
Reports from scanners and automated tools
Reports out of the subdomains app.dailybot.com, api.dailybot.co, and api.dailybot.com
Self-exploitation (like token reuse and console scripting)
Social engineering or phishing attacks targeting users or staff
Vulnerabilities related to other systems (i.e. help.dailybot.com) which is a Zendesk app
Found a bug already?
Please submit it below so we can take care of it.
Submit a Vulnerability