
hostinger
External Program
Submit bugs directly to this organization
#HOSTINGER BUG BOUNTY REWARD PROGRAM
PLEASE READ THIS AGREEMENT CAREFULLY, AS IT CONTAINS IMPORTANT INFORMATION REGARDING YOUR LEGAL RIGHTS AND REMEDIES. Last Revised: 2024-01-24
#RESPONSIBLE DISCLOSURE POLICY Hostinger encourages the responsible disclosure of security vulnerabilities in our services or on our website. In order to facilitate the responsible disclosure of security vulnerabilities, we agree that if, in our sole discretion, we conclude that a disclosure meets all of the guidelines of the Hostinger Bug Bounty Reward Program, Hostinger will not bring any private or criminal legal action against the disclosing party.
#BUG BOUNTY REWARD PROGRAM POLICY AND TERMS Our team of dedicated security professionals works vigilantly to help keep customer information secure. We recognize the important role that security researchers and our user community play in helping to keep Hostinger and our customers secure. If you discover a site’s or product’s vulnerability, please notify us using the guidelines below.
#PROGRAM TERMS Please note that your participation in the Bug Bounty Reward Program (“Bug Bounty Program”) is voluntary and subject to the terms and conditions set forth on this page (“Program Terms”). By submitting a site or product vulnerability to Hostinger, you acknowledge that you have read and agreed to these Program Terms. These Program Terms supplement the Terms of Service and Privacy Policy and any other agreement you have entered with Hostinger. The terms of those Hostinger agreements will apply to your use of and participation in the Bug Bounty Program as if fully set forth herein. If any inconsistency exists between the Terms of Service, Privacy Policy and these Program Terms, these Program Terms will prevail, but only with regard to the Bug Bounty Program. To encourage responsible disclosures, Hostinger commits that if we conclude, in our sole discretion, that a disclosure respects and meets all the guidelines of these Program Terms, Privacy Policy and Terms of Service, Hostinger will not bring a private action against you or refer a matter for public inquiry. As part of your research, you shall not modify any files or data, including permissions, and shall not intentionally view or access any data beyond what is needed to prove the vulnerability.
Hostinger will make its best effort to adhere to the following response targets: Type of Response - Business days First Response - 2 working days Time to Triage - 5 working days Time to Bounty - 14 working days Time to Resolution - depends on severity and complexity
#TESTING CREDENTIALS
To prevent abuse of shared credentials, we do not provide access to shared testing accounts. Instead, Bug Bounty Program participants must register a new account at hostinger.com. Participants can receive a coupon covering one month of our Premium Shared Hosting plan. To claim your coupon, please contact our Security team at [email protected] and include the following details in your message:
Once verified, our team will provide you with a coupon code that covers all expenses for one month of Premium Shared Hosting.
#THE FOLLOWING HOSTINGER DOMAINS ARE IN SCOPE:
Domains not listed above are out of scope.
*Note: we only reward vulnerabilities caused by our systems. Issues related to the cPanel platform itself are not eligible for rewards.
We have launched new Agency hosting plans that are built entirely on our H5G infrastructure, which is designed specifically for WordPress hosting. These plans provide complete site isolation to boost security and performance. They also facilitate access sharing for each site, supporting smooth collaboration among team members.
Since the Agency plan is fully powered by H5G, its security testing scope (including Bounty Payments) falls under our existing H5G Infrastructure scope. We invite researchers to help identify potential vulnerabilities.
To participate in testing our new hosting plans, please email [email protected] and ask for a coupon for the Agency plan testing. Include the email address you used to register for Hpanel in your email.
#ELIGIBILITY REQUIREMENTS To be eligible for the Bug Bounty Program, you must not:
#DISCLOSURE GUIDELINES By providing a submission through HackerOne or agreeing to the Program Terms, you agree that you shall not publicly disclose your findings or the contents of your Submission to any third parties in any way without Hostinger's prior written approval. Failure to comply with the Program Terms will result in immediate disqualification from the Bug Bounty Program and ineligibility for receiving any Bounty Payments.
#QUALIFYING VULNERABILITIES: Hostinger will accept a report of any vulnerability that substantially affects the confidentiality or integrity of any eligible Hostinger service. Eligible vulnerabilities include, but are not limited to:
#NON-QUALIFYING VULNERABILITIES: Any domain not listed in the policy scope is out of scope for the purposes of the Bug Bounty Program, as is all hosted customer content and third-party programs and plug-ins. The following actions do not qualify for the Bug Bounty Program and should not be tested by researchers participating in the Bug Bounty Program:
#BUG SUBMISSIONS REQUIREMENTS Required information For all submissions, please include:
#REMOTE CODE EXECUTION (RCE) SUBMISSIONS GUIDELINES: Failure to meet the below conditions and requirements could result in a forfeiture of any potential Bounty Payment.
#BOUNTY PAYMENTS You may be eligible to receive a monetary reward (“Bounty Payment”) if: (i) you are the first person to submit a site or product vulnerability; (ii) that vulnerability is determined to be a valid security issue by Hostinger's security team at their sole discretion; and (iii) you have complied with all Program Terms. Bounty Payments, if any, will be determined by Hostinger in Hostinger's sole discretion. In no event shall Hostinger be obligated to pay you a bounty for any Submission. All Bounty Payments shall be considered gratuitous. All Bounty Payments will be made in United States dollars (USD). You will be responsible for any tax implications related to Bounty Payments you receive, as determined by the laws of your jurisdiction of residence or citizenship. Hostinger will determine all Bounty Payments based on the risk and impact of the vulnerability. The minimum bounty amount for a validated bug submission is $100 USD, and the maximum bounty for a validated bug submission is $25000 USD. Hostinger security team retains the right to determine if the bug submitted to the Bug Bounty Program is eligible. All determinations as to the amount of a bounty made by the Hostinger Bug Bounty Team are final. Bounty Payment ranges are based on the classification and sensitivity of the data impacted, ease of exploit, and overall risk to Hostinger customers and the Hostinger brand and determined to be a valid security issue by Hostinger's security team.
#RETESTING
Please note that we reserve the right to request or decline retesting of reported issues at our discretion, based on our internal assessment and priorities. Our decision will take into account factors such as the severity of the issue, the quality of the initial report, and our current resource availability.
To recognize the additional effort involved in retesting, we offer retest bounties as follows:
#OWNERSHIP OF SUBMISSIONS As a condition of participation in the Bug Bounty Program, you hereby grant Hostinger, its and affiliates a perpetual, irrevocable, worldwide, royalty-free, transferrable, sublicensable (through multiple tiers) and non-exclusive license to use, reproduce, adapt, modify, publish, distribute, publicly perform, create derivative work from, make, use, sell, offer for sale and import the Submission, as well as any materials submitted to Hostinger in connection therewith, for any purpose. You should not send us any Submission that you do not wish to license to us. You hereby represent and warrant that the Submission is original to you, and you own all rights, titles, and interests in and to the Submission. Further, you hereby waive all other claims of any nature, including express contract, implied-in-fact contract, or quasi-contract, arising out of any disclosure of the Submission to Hostinger. In no event shall Hostinger be precluded from discussing, reviewing, developing for itself, having developed, or developing for third parties, materials that are competitive with those set forth in the Submission irrespective of their similarity to the information in the Submission, so long as Hostinger complies with the terms of participation stated herein.
#TERMINATION In the event (i) you breach any of these Program Terms or the Terms of Service of the Hostinger; or (ii) Hostinger determines, in its sole discretion that your continued participation in the Bug Bounty Program could adversely impact Hostinger (including, but not limited to, presenting any threat to Hostinger's systems, security, finances and/or reputation) Hostinger may immediately terminate your participation in the Bug Bounty Program and disqualify you from receiving any Bounty Payments. Please follow these Program Terms.
#CONFIDENTIALITY Any information you receive or collect about Hostinger, Hostinger employees, or any Hostinger customer through the Bug Bounty Program (“Confidential Information”) must be kept confidential and only used in connection with the Bug Bounty Program. You shall not use, disclose, or distribute any such Confidential Information, including, but not limited to, any information regarding your Submission and information you obtain when researching the Hostinger sites, without Hostinger's prior written consent. Any disclosure of Confidential Information outside of this requirement will result in immediate removal from the Bug Bounty Program.
#INDEMNIFICATION In addition to any indemnification obligations you may have under the Terms of Service, you agree to defend, indemnify and hold Hostinger, its affiliates, and the officers, directors, agents, employees, and suppliers of Hostinger, harmless from any claim or demand (including attorneys’ fees) made or incurred by any third party due to or arising out of your Submissions, your breach of these Program Terms and/or your improper use of the Bug Bounty Program.
#CHANGES TO PROGRAM TERMS The Bug Bounty Program, including its policies, is subject to change or cancellation by Hostinger at any time without notice. As such, Hostinger may amend these Program Terms and/or its policies at any time by posting a revised version on our website. By continuing to participate in the Bug Bounty Program after Hostinger posts any such changes, you accept the Program Terms, as modified.