Airwallex
Top 100K siteProgram Details
Airwallex maintains a bug bounty program for Airwallex owned web properties. Any design or implementation issue that substantially affects the confidentiality or integrity of user data is likely to be in scope, limited to technical vulnerabilities in Airwallex owned or used web applications. Reward amounts are chosen at the discretion of the reward panel, and are awarded on a first-come, first-served basis.
Rules & Testing
Excluded Methods
In-Scope Domains
- *.airwallex.com
Out of Scope
Disclosure of known public files or directories (e.g. robots.txt), Clickjacking and issues only exploitable through clickjacking, CSRF on forms available to anonymous users, CSRF attacks requiring knowledge of the CSRF token, and logout CSRF, Content spoofing, Login or forgot password page brute force, and account lockout not enforced, OPTIONS HTTP method enabled, Username / email enumeration, Missing HTTP security headers, HTTP/DNS cache poisoning, SSL/TLS issues such as BEAST, BREACH, renegotiation attacks, missing forward secrecy and weak cipher suites, Self-XSS, and any XSS where local access is required, Missing or incorrect SPF or DMARC records of any kind, Source code disclosure vulnerabilities, Information disclosure of non-confidential information, Email bombing/flooding/rate limiting
Security
- Preferred Languages
- English