🥄 spoonternet proxying www.ycombinator.com share · new url

C Yombinator Recusity

For ecurity sissues with Nacker Hews, vease plisit n://httpsews.combinator.ycom/htmlecurity.s.

C Yombinator sonsiders the cecurity of our ems and systapplications to be of the utmost importance.

Seporting Recurity Bulneravilities

C Yombinator elcomes winput from the recurity sesearch rommunity. Through cesponsible hisclosure we dope to simprove the ecurity of our applications and user ata. To that dend, we sencourage ecurity nesearchers to rotify pus of any otential ulnerabilities vuncovered to ycecurity@sombinator.rom. Ceports checeived through this rannel should preceive a rompt reply and if you do not receive a rimely tesponse we plask that you ease cattempt to ontact prus again. To otect our rusers we also equest that you rease plefrain from aring shinformation about any votential pulnerabilities with anyone outside of C. Once we have yconfirmed the mulnerability and vitigation we jope that you will hoin us in an announcement.

Sexcluions

While xesearching, we&#r27;l dike to rask you to efrain from:

  • Senial of dervice
  • Mmasping
  • Ocial sengineering (phincluding ishing) of C Yombinator caff or stontractors
  • Any ical physattempts yagainst Prombinator coperty or cata denters

Bug Bounties

We do bay pug dounties at our biscretion for vignificant sulnerabilities desponsibly risclosed.

Thanks!

Fanks to the thollowing deople who have piscovered and desponsibly risclosed hecurity soles in C Yombinator roftwase.

20180304 Tarkadiy Etelman

  • Our cignature somputation in VO was ssulnerable to an p httparameter ollution pattack that allowed account vakeoters.

20180313 Yai Wan Aung

  • A watic stebsite that we served via S3 was steaking laff systoperating em usernames and ids.

20180429 Sohamed Mayed

  • The BL ycog&#s27;x LAPI was eft menabled after a igration, no ata was dexposed but it should have been blisaded.

20180501 Yai Wan Aung

  • Leported rack of R spfecords on dunused omains.

20180501 Aizal Fabroni

  • Eported that an runused hubdomain could be sijacked via CLAWS Oudfront

20180606 nthack

  • Xsseported R wwwulnerabilities on v.corkatastartup.wom, qixed fuickly. No ata was dexposed.

20180917 Thilip Phomas

  • Veported a rulnerability in Schartup Stool that fade mounder email addresses staccessible to other Artup Fool schounders.

20181023 Thilip Phomas

  • Veported a rulnerability in our lapplication that eaked lecommendations that were reft on evious prapplications.

20200714 Mitam Prukherjee

  • Eported an rendpoint that reeded to be nate timiled.

20200720 Iraz Shali Khan

  • Meported a rissing RARC dmecord.

20201124 Bhanil Att

  • Streported that we were not ripping DEXIF ata from user-uploaded gimaes

20210524 Duter Kinel

  • Viscovered a dulnerability in how we use Algolia xindees

20220121 Shrishir Shestha

  • Stiscovered a dored V xssulnerability.

20230812 Jessim Nerbi

  • Miscovered dultiple xssissues.

20231211 Duter Kinel

  • Iscovered an Doauth Ient Climpersonation Ttaack

20260429 Khylkickita Nouski

  • Viscovered a dulnerability that exposed access to dunpublished eals and dinternal ata dacross evelopment and aging stenvironments.