Responsible Disclosure of Security Vulnerabilities
Reporting security issues ¶
We want to keep iFixit safe for everyone. If you've discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.
We'll work with you to make sure that we understand the scope of the issue, and that we fully address your concern. If you believe you have discovered a vulnerability or have a security incident to report, please email security@ifixit
Please act in good faith towards our users' privacy and data during your disclosure. When testing for vulnerabilities
We're happy to provide a reward to users who report valid security vulnerabilities
- Be the first person to responsibly disclose the bug.
- Report a bug that could compromise our users' private data, circumvent the system's protections, or enable access to a system within our infrastructure. Examples include:
- Persistent Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF/XSRF)
- Broken Authentication
- Circumvention of our framework's privacy and permission models
- Remote Code Execution
Our security team will assess each bug to determine if it qualifies.
Thanks! ¶
Thank you for your help with keeping the iFixit community safe. We really appreciate it.
Here are people who have responsibly disclosed vulnerabilities in the past:
2013 ¶
- Sachin Kediyal
- Narendra Bhati - Cyber Octet Pvt. Ltd.
- Jon - Bitquark
- Riaz Ebrahim
- Tejash Patel - @tejash1991
- Sasi Levi - @sasi2103
- Mahadev Subedi
- Sebastian Neef & Tim Schäfers - @internetwache
- Abhinav Karnawat - \/ w4rri0r \/
- Sabari Selvan - @EHackerNews
- Malte Batram - @_batram
- Priyal Viroja - aN0_pr!+Z
- Krutarth Shukla
- Himanshu Kumar Das
- Mariano Di Martino
- Ajay Singh Negi
- Piyush Malik - @ThePiyushMalik
- Ritesh Arunkumar Sarvaiya - defencely
- Kyle Swidrovich
- Yuji Kosuga
- Shashank kumar
- Atulkumar Hariba Shedage - defencely
- Frans Rosén - @detectify
- Emanuel Bronshtein - @e3amn2l
- Jaume Llopis Pujal
- Kamil Sevi - @kamilsevi
- Simran Jeet Singh
- Tushar Kumbhare - Anti Hacking Anticipation Society
- Subho Halder - @sunnyrockzzs & Aditya Gupta - @adi1391
2012 ¶
- Tushar Kumbhare - Anti Hacking Anticipation Society & Thamatam Deepak - Mr.47
- Jaume Llopis Pujal
- Jacob Soo Lead Re - @Gunther_AR
- Yuji Kosuga
- Adam Ziaja
- Alok. J. Sudhakar - @AnnonymizerAlok
- Adino Namchu
- Chiragh Dewan
- Rafay Baloch - http://rafayhackingarticles.net
- Himanshu Sharma - DCE, Gurgaon
- Krutarth Shukla
- Harsha Vardhan Boppana - Login Security Solutions
- Atulkumar Hariba Shedage - defencely
- Rakan Alotaibi - @hxteam
- Kamil Sevi - @kamilsevi
- Nikhil Kulkarni
- M.R.Vignesh Kumar
- Prajal Kulkarni
- Ajay Singh Negi
- Himanshu Kumar Das
- Elvin Gentiles
- Emanuel Bronshtein - @e3amn2l
- Maxim Rupp
- Avram Marius Gabriel - RandomStorm