Responsible Disclosure Policy
Introduction
Kitabisa.com welcomes feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you. This policy outlines steps for reporting vulnerabilities to us, what we expect, what you can expect from us.
Systems in Scope
-
kitabisa.com
-
accounts.kitabisa.com
-
core.kitabisa.com
-
donasi.kitabisa.com
-
galangdana.kitabisa.com
-
galang-dana.kitabisa.com
-
geni.kitabisa.com
-
waf.teler.app
Out of Scopes
-
*.kitabisa.com
-
blog.kitabisa.com
-
*docs.kitabisa.com
-
imgix.kitabisa.com
-
maintenance.kitabisa.com
-
static*.kitabisa.com
-
*.ktbs.dev
-
*.ktbs.in
-
*.ktbs.io
-
*.kitabisa.cc
-
*.kitabisa.org
- Assets and/or other equipment not owned by parties participating in this policy.
Testing is only authorized on the targets listed as in scope. Any domain/property of Kitabisa not listed in the targets section is out of scope. This includes any/all subdomains not listed above. Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority. If you think it demonstrably belongs to Kitabisa, use Official Channels to discuss with us.
Our Commitments
When working with us, according to this policy, you can expect us to:
-
Respond to your report promptly, and work with you to understand and validate your report;
-
Strive to keep you informed about the progress of a vulnerability as it is processed;
-
Work to remediate discovered vulnerabilities in a timely manner, within our operational constraints; and
-
Extend Safe Harbor for your vulnerability research that is related to this policy.
Our Expectations
In participating in our vulnerability disclosure program in good faith, we ask that you:
-
Play by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail;
-
Report any vulnerability you’ve discovered promptly;
-
Avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience;
-
Limit the duration of the fundraising campaign to 1 day during testing;
-
Use only the Official Channels to discuss vulnerability information with us;
-
Provide us a reasonable amount of time to resolve the issue before you disclose it publicly;
-
Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope;
-
If a vulnerability provides unintended access to data; Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information;
-
You should only interact with test accounts you own or with explicit permission from the account holder; and
-
Do not engage in extortion.
Official Channels
Please report security issues via [email protected], providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue.
The Kitabisa security team recommends to use this PGP key to sign all security notifications and encourages others to use this key when sending sensitive information to us.
PGP fingerprint: F582 2A71 4345 99C0 70EB 472A 1FF2 8907 24C0 D9F5
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBGHo5DcBEACxufJTxDylHe1yepMP8O5LhmGWrCjv2U/gBnpiJWHvO2+jXVa1 pWIJHJ0b1amelMqbInEB5268u47mGFj1oYtglmR1zc7VXd1bqk5+eN9xTVhKwyTK wCOnXGXgqANnnJz8GK1WxsDcEixJ6Yvg2qWZSKsWsoblWsx5FT4HKgUeLdG+pqMn EopcLznVdLlya2NmovhPp49o4OeSr1sBbRWALhRINNSLniFBYozF6REUOjRUp0Yi 48z+Xdy5vVzgo9mQEgAT7C2v039b5kja6yzCYpq98EjrnMcQrIcni9M8yC4Vw3Tx kf3V3di3ylhCV9Op3IDTWS6XE+czf4oamXTZ+czG6ecLS8vBYFU2yBrcKEsBropa VoBT710frVteL48M26AF+oI1X0u0ZAJG+6WWVOZ5oVWTN9BQoo/3u06jqZqFAaX+ 2e1mF1pOl4g1gMfnhA5b6hyWawnCVj0OtqhFL/kAQTGSYT9GNFc2/q4fB9TzYGwB afY6JJQVVXJD/ACLyEiAFfoKrANY9nbaOVETxbz3VCUJVsDHI3xSb7Ra6Tql39dg ZbsWu4N9gRRvI+Z1NgzF07lAh0vACWLm8vD1ZyiFDNht3k9wBLCLlS7dEM9caW9l UZOMKHN48bhWfbxHQ6qH7GKPSIQXqUIOS13QOq0/SfBJ2bIOk0Bi0RSMhQARAQAB tEFLaXRhYmlzYSBTZWN1cml0eSAoUmVzcG9uc2libGUgRGlzY2xvc3VyZSkgPGlu Zm9zZWNAa2l0YWJpc2EuY29tPokCOAQTAQIAIgUCYejkNwIbAwYLCQgHAwIGFQgC CQoLBBYCAwECHgECF4AACgkQH/KJByTA2fUi+RAAkvPPJxUVIzfLXaqRVEyxofPn W8QJXBB1mLWuolIlsnaXz8yjvpa4475eF6PTg/474elhQ1QFQjFaziWCc9Y5aKtU uoykwwSIuCCLKDgjYTKXb2993FH97LD8D1vDC/11P+UUkwocVW5SQU0U/tPzOS9K kmyz74SDb+6Uvph8Zx/uNmnVGqNQwPXwPXdszabeiXJhXZ20VJ+ZzFezCJsqq/ge qfDFpY7HArKENmRbJzOelmHPU2QUSOOc9g+5kKu2MQqeaCPfI6L+5kIjNYOILbiH 84D8JR8A+RuJ5yYmDi5Llz2xk1Zf8x4kBOxaXTNd5JIWcQJAyi//2dlMmSmWrpDH WsOy2e4HzMB/6edajzO33FHUS2L+IeSTIhPar/b8azuBUugmxYA2InAObJ4hquWs R9qEQjZDi/5EfUAVRQPkG8ZYgcvNaDjrUWiwKGsL640COHQqTXNH9Q90pdi/5UwL L7zTiiZZEKgMb80PtVqQ1R/g+y5WyYyUmdhP8EUQnx1UpCcJZ/ZgU0hjAAoBdUxO BAlkV6aUgQGSzfhGjqgFOhQx4cn5iI1rQB67o/slufp32Uj/jS7eSSKeDC5ZZG8s 9dc9Ke6ZaNeeLN88s1BkNEXf5hl3BHuvEznQaYLHmGpmEVTQ62xoJNOOG68PHsJp EToltX5M7UF2/pCylaq5Ag0EYejkNwEQAJb2VpUcQppAV4P3wrhWBFAvrlnNDS7V BF8KsjTyOh+WCoHjQ2xEKjw96LIzvbaDBGd3DVBqpnipkOMuwvYBmyoRBOg+7u9d 5mLle43cna8Iiqra5A1icysg0wCGK7Dui+hrHLKb4jJKiwwNBymDCcyyUYAVkcL4 ArA3MchvrLKRxGXBOGiu5Eo5lBSnF6DFBAMj9M5P9Ia0+GjNT3sMBE+3ip5vKmdb /2rGKv2Ejsz25XEvC/XXCXe6euHfznddj82flLKCll7wuRctY2gpJgXriV8zDeiw UuTxKKe4+eh1vF45gpbgnsTca4CyQhXw3AL2k38J6okagMlntwlcD/QivyqUDSHd iRZ8Q8Jm5k2C7lv8UN6spaDe5Pfxt2r4qSli0sw9w4mZOguSbiwwiB3NcO62RAsH Sz+ROVJcOTXl7a34vnxnF4o4rHA3UMNQNQG2vwc9e57ebHhtSvuAOsvss4KhL/Py GR7NQBmdiFOxUWFt/UyFij5RkLZZJ973FmA8OyQEWQJ7ThBPIX13/wVhJKdxP87J CAb2OLdht/94mfX24ZV1Tx8YIsK+CVC8AtOh/H43EbLSaTPFS9K9UXf1d/aQgYvZ ss4ysABn5Nuxh8y7W9e/hZ5McfPVzQAumg08/P18cLaCz0BKvT988hfkiE3xal3w jvjWFyiskeVfABEBAAGJAh8EGAECAAkFAmHo5DcCGwwACgkQH/KJByTA2fVscxAA oRtIbPckXaf47P2gld7Fc4eSI1WsaRmEf5rX7jgUJgEyQfs7VApkd5kZ8ICiQlyQ wsG544yNdYN5zHNjd9mFfGSl1RZsesD4dV39x0sjN0S+uMZ6mSu80yqPcrvu5UZL 67KGtKhT6jhdtPx8D+2ADAUaBuvUpEM1GQXCGiXEWS6jEW53X9heMwYQE2KvxILk NAeYqSerAMaTwfd04wRPjsZCvo4jd2XN5MQMI4WUZ8V01R8nL/bwTq/QaJYJuUI+ ZXQ/m1Zgqi/dXl/aLD9JoQj9cQxNO6/SqLCjZscKjLdmD5gASmphktHyby9uS3Lz MEsqpv6q0voKZhjGvDH0AMVT3qMhSCGpmAoiFbP/xnJG16ucxmJRlOje6y7WkDoI eNwhfha804wEb0tKDBi1F0vQaqgrhPNL9b8AFQ13k91ttKw94PMPxIUT48a/34am nuxOjo1thT/9MZewV32Znno24Pge0dIzZylrmxk/4mBHMfkX+ir0K7LwnBpyPdd1 R3cVkwOkXb7bfCuZVPr0mZDdBJlFQcOoDRteoh37F50h8j6IMKVh/zibHIUglFY1 a4xNYN2bvze8v9zKtkTj1XbqhA4uHPWVzBspEEfK2GGgklNcUVkXSHz4f4ne6tvS r2jGg5JADz0cI+rH3AfbEZueywhGJtANVOTxsCoJHYE= =aheQ -----END PGP PUBLIC KEY BLOCK-----
Safe Harbor
When conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be:
-
Authorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
-
Authorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;
-
Exempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis; and
-
Lawful, helpful to the overall security of the Internet, and conducted in good faith.
You are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.
Note that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties.