Hall Of Fame
We are grateful to the following people for having reported valid security bugs and for helping us make Internshala safer.Kaushal Bhardwaj
- Misconfiguration of policy - reported on 15
th Feb, 2023
Shuvamoy Roy
- Information Disclosure - reported on 18
th Jan, 2021
Rohit Soni
- Information Disclosure - reported on 10
th Aug, 2020
Ritik Chaddha
- Information Disclosure - reported on 26
th Jun, 2020
Pratik Dabhi
- Stored XSS - reported on 22
nd Jun, 2020
Raju kumar(Mrcyberwarrior)
- Misconfiguration of policy - reported on 28
th Feb, 2020
Dewanand Ram Vishal
- Misconfiguration of policy - reported on 26
th Feb, 2020
Rahul Mali
- Open Redirection - reported on 10
th Oct, 2019 - Referral count issue - reported on 10
th Oct, 2019 - XSS - reported on 10
th Aug, 2016
Aditya Sharma
- XSS - reported on 18
th Oct, 2018
Deepanshu Tyagi
- XSS - reported on 6
th Jul, 2018
Karan Saini
- Bypassing E-mail Verification - reported on 6
th Feb, 2018
Nisheal A John
- Stored XSS - reported on 20
th Nov, 2017
Ishaq Mohammed
- CSRF bypass - reported on 11
th Sep, 2017
Noman Shaikh
- Data Manipulation using CSRF bypass - reported on 24
th Mar, 2017
Shrey Sethi
- Information stealing using XSS - reported on 6
th Jan, 2017
Mohit Soni
- Click Jacking - reported on 29
th Nov, 2016
Nandhakumar
- SQL Injection - reported on 10
th Aug, 2016
Internshala Bug Bounty Program
If you discover a security issue in our website or app, please report it to us confidentially in order to protect the security of our products. Please email the details to our technical team at tech@internshala.com. We will get back to you once we have investigated it completely.
Guidelines of our bug bounty program-
- Please do not use automated tools in your research without our explicit consent
- We must be able to reproduce the security flaw from your report. Unclear or vague reports are not eligible for bug bounty. Reports that include clearly written explanations and working code/ Proof of concept videos are more likely to be eligible for bug bounty
- The bug must exist in Internshala's codebase.
- Please avoid privacy violations, destruction of data and interruption or degradation of our service during your research
- Please give us reasonable time (upto 1 week) to investigate and respond to your report
- We try to investigate, fix and credit bugs in a timely manner. However, it may be possible that fixing a bug may take time and the same bug may be reported by multiple researchers. In such a case, we will only credit the first researcher to report an issue
-
We reserve the exclusive right to determine whether or not a bug/ vulnerability report is serious enough to warrant a reward. We are not interested in most bugs of the following type-
- Denial of Service vulnerabilities (DOS)
- Possibilities to send malicious links to people you know
- Security bugs in third-party websites that integrate with Internshala
- Mixed-content scripts
- Rewards: If a bug/vulnerability is significant enough to warrant addition to our bug bounty program, we will send you an Internshala T-shirt and add your name to our hall of fame.