Skip to content

Security: anthro-id/security-disclosure

SECURITY.md

img

Awooo! ๐Ÿบ ๐ŸฆŠ ๐Ÿ›
Welcome to Anthro Indonesia's security disclosure program!

Here, we prioritize privacy and security very seriously and we've been conscious about it since day one, because we're aware that furry nerds are so good at IT stuff and we'd love to see that in-action here!

That being said, we encourage everyone (including furry nerds, bug hunters, researchers, or you ๐Ÿ‘€) to participate in our program and responsibly find, disclose, and help us resolve security vulnerabilities.

Since this is our first program, we'll give you a pretty much straightforward sets of rules that benefits you and us.

Our Approach

Anthro Indonesia developers will not take any legal action against everyone for disclosing vulnerabilities.

Since this Platform is built by up to two furries, we do not guarantee that we'll be resolving this in a day, so we set our time limit up to 7 days, excluding holiday or national days. But still, if it's critical, we'll respond it ASAP.

We have rights to modify or rewarding you based on our believe or view in the severity.

Rewards

Unfortunately, at the moment, due to the Anthro Indonesia's funding structure, it is not currently possible for us to offer a paid bug bounty program.

As a token of appreciation, we can give you a honorable mention in our Platform.

And for medium-critical severity reports, we can ship an electronic certificate signed by PSrE Indonesia to your Anthro Indonesia's account. The eligibility is to have at least 3 medium and/or 1 critical severity reported issues.

If you don't know what PSrE Indonesia is, it's an Indonesia's state-recognized certification authority under the Ministry of Communication and Digital Affairs (Komdigi). The authenticity can be validated here.

Program Rules

  • We're currently accepting vulnerability reports in English (preferred) or Indonesia language.
  • Only test on your own account, don't involve others, like at all.
  • We do not accept scanners or automated tools to find vulnerabilities, this includes using tools like Burp Suite.
  • We do not accept any actions that can potentially harm our properties, such as flooding, DoS/DDoS, brute forcing, timing attacks, and more to mention.
  • After submission, we do not encourage you to share or publicly disclosed the vulnerabilities until we give you a green light, such as posting it to your social media.

Report Submissions

At the moment, every issues must be submitted through the GitHub Security Advisory. You have to explain the issue thoroughly, like what impacts it, how big the blast radius is, what users should do to avoid the bug at the moment, etc.

We do not accept an AI-generated submission. The report must be originally discovered by your own procedures.

We do not accept a report that is either already known by us or previously submitting. So before submitting, please check the submissions history first to avoid duplicates.

Remember that, as we mentioned before, sharing or publicly disclosed the issues to the Internet such as social media before a green light from us, we'll consider you ineligible for the reward. But still, we'll patch the issues that you submitted anyway.

With all that being said, we'll try our very best to make sure everyone who puts their time and effort to responsibly disclose their findings are correctly and appropriately rewarded!

Out of Scope

When reporting a vulnerability, please consider the (a) attack scenario, and (b) the impact. The following issues are generally considered out of scope, including but not limited to:

  • Account, email address, or any IDs (this includes article IDs) enumeration that doesn't reveal any sensitive information.
  • Any endpoint that allows you to determine the validity of the ID.
  • Attacks requiring MITM or physical access to a user's device.
  • Attacks where the intention is resource exhaustion.
  • Brute-force attacks.
  • Clickjacking.
  • Content spoofing and text injection.
  • CSRF vulnerabilities.
  • Intentionally exposed API keys such as Google Maps Embed API key.
  • Linking to an unsafe file or resource which requires the user to interact to open the link.
  • DNSSEC or SPF/DKIM/DMARC email records.
  • Partially missing checks on forms, such as missing maximum lengths on some text inputs or autocomplete attributes.
  • Publicly accessible login panels.
  • Reports from scanners and/or automated tools.
  • Reports on the subdomain such as status.anthro.id or *.cdn.anthro.id
  • Self-exploitation, such as scripting in the browser console.
  • Social engineering or phishing attacks targeting users or Anthro Indonesia developers.

Preferred Report Template

### Details
[The summary of the vulnerability report here, including details too.]

### PoC
[This is a Proof of Concept. Send us instructions so we can reproduce the report.]
[You can also include images, videos, and/or GIFs.]

### Impact
[Tell us what's the impact of this vulnerability and how serious is it.]

### References
[You can put links that are related to this vulnerability, such as GHSA or CVE link.]
[This is optional, you can remove this section.]

Safe Harbor

If you are doing it in a good faith (in our sole discretion), once again, we will not pursue any legal action, subject to Anthro Indonesia's compliance with applicable Indonesian laws. To qualify for safe harbor, your report must be unconditional and may not involved extortion or any threats.

Policy Changes

We reserve the rights to change this policy at anytime with or without notice.

Feedbacks

If you have questions, concerns, or get to know more about our program, feel free to email us at security@anthro.id.

Happy hunting, awoo!~

Credits

A huge thank you to Zeru ๐Ÿ–ผ๏ธ for the banner commission!

There aren't any published security advisories