Skip to content
TORNLIFE More

Bug bounty program

Started by Chedburn [1] Admin on in Announcements.

1 replies · 98.1k views · thread synced · 3 days ago · View on torn.com
About this thread

Posts archived: 2 / 2 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
2
Discussion span
→
People posting
1
Likes on archived posts
0
Posts by staff, officers and moderators
2
Authority score
93 / 100
Historical score
78 / 100
Story score
56 / 100
Engagement score
71 / 100

Mentioned in this thread

Batman [984129] ×1 Bug [1455582] ×1 Mauk [1494436] ×1 Shane [1514924] ×1 mgthura [1898201] ×1 martianmellow12 [1992729] ×1 MikePence [2029670] ×1 highlight [2123910] ×1 Kwack [2190604] ×1 CockyNudist [2209950] ×1 Bacurau [2245633] ×1 Frodo [2282199] ×1

Chedburn [1] Admin Developer
Citizens,

I would like to announce our bug bounty program.

We're now offering rewards of up to $10,000 USD for the disclosure of serious vulnerabilities. Rewards can be paid via PayPal in most currencies, Bitcoin, or of course the equivalent value in Donator Packs.

Generally we're interested in processes that can result in the unintended loss of data / changing of data / disclosure of private data, processes that cause site-wide slowness / degradation of performance for all other players, and exploits that provide a player with a clear unfair advantage, for example item / money duplication.

Critical - $10,000 USD
For example, a serious vulnerability that if abused to maximum effect, could have forced us to restore all users to a previous backup after significant loss or corruption of data which cannot be manually resolved.

High - $2,500 USD
For example, a vulnerability that can provide a clear unfair advantage to a player, such as item / money duplication. Serious forms of SQL injection. Vulnerabilities that can result in slowness / performance issues for all other players. I.e. Something that we would have generally spotted ourselves over time and could resolve manually.

Medium - $1,000 USD
Other less significant vulnerabilities / exploits that could deteriorate the game for other players in terms of site performance, gameplay or balance. Limited blind SQL injection. Something that was previously unknown to us that we would still want to take immediate action on.

In some cases, at our discretion, we may also provide smaller rewards for discoveries that we don't feel are severe enough to meet the above tiers.

We'll be open and honest about the severity of a reported vulnerability even if you've not been able to confirm its potential impact. Once reported, we'll investigate to understand how significant it is. We are comfortable with these values, and very happy to monetarily reward those who find such vulnerabilities.

If you are unsure if a vulnerability you've found meets the criteria for a reward, you can provide us with a general summary / level of potential risk and we'll be able to advise the estimated reward value before you reveal it.

Anyone who receives a Bug Bounty reward will also receive the Bug Swatter item and be added to a list (anonymized if they wish).

If an exploit has been used by someone who comes forward, assuming it can be accurately reversed with no remaining advantage, leniency will certainly be shown and it's unlikely any punishment will be required.

I'll also include our Policy here.


If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.

Disclosure Policy
- Let us know as soon as possible upon discovery of a potential vulnerability, and we'll make every effort to quickly resolve the issue.
- Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.

Exclusions
While researching, we'd like to ask you to refrain from:
- Denial of service
- Spamming
- Social engineering (including phishing) of TORN LTD staff or contractors
- Any physical attempts against TORN LTD property or data centers

Safe Harbor
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Thank you for helping keep TORN and our users safe!


Vulnerabilities can be reported in-game to any staff members who will pass it up to management, or to our webmaster@torn.com email account.

Edit: As of 29/10/2021 we've updated our rewards. Critical: $2,500 -> $10,000. High: $1,000 -> $2,500. Medium: $500 -> $1,000

Thanks.
Chedburn [1] Admin Developer

Bug bounties rewarded to date

Bug [1455582] - 03/02/20 - $1,000
Vulnerability on an entry field which had insufficient sanitization, as well as some other more minor issues.

Mauk [1494436] - 05/02/20 - $750
XSS exploit bypassing CSP by directly loading internal files which should have been restricted.

Bug [1455582] - 06/02/20 - $1,000
Vulnerability on an entry field which had insufficient sanitization, allowing blind injection / restricted user searches.

Anonymous - 17/02/20 - $1,000
Vulnerability in Keno allowing duplicate entries of a single number to force an illegitimate win.

Juggernaut-XMeN [1898201] - 27/02/20 - $750
Vulnerability on racing system allowing limited injection, as well as some other more minor issues.

Bug [1455582] - 29/02/20 - $1,000
Vulnerability bringing to light legacy code issues allowing injection despite sanitization.

BodyHugger [2088243] - 09/03/20 - $1,000
Discovery of a HTTP response which was including private information & app login URL occasionally.

Shane [1514924] - 23/03/20 - $1,000
Ability to sell a single Weapon or Armor multiple times at Big Al's Gun Shop, duplicating funds.

Juggernaut-XMeN [1898201] - 26/03/20 - $500
Blind SQL injection via unprotected input on the Item Market.

MikePence [2029670] - 27/03/20 - $500
Vulnerability in High-low providing additional information in response output for a potential minor advantage.

Juggernaut-XMeN [1898201] - 27/03/20 - $1,000
Blind SQL injection via Organised Crimes and Bookies.

MikePence [2029670] - 27/03/20 - $500
Racing conditions in faction management allowing withdrawal of negative funds from vault and duplicate OCs.

Juggernaut-XMeN [1898201] - 20/04/20 - $500
Blind SQL injection via faction permissions management system.

Juggernaut-XMeN [1898201] - 20/04/20 - $500
Notified us that web.archive.org was revealing analytics areas (that we thought were hidden) for internal use.

Anonymous - 21/04/20 - $500
Unintended response revealing money-on-hand & game entry passwords for those in Russian Roulette lobbies.

nostarch887 [2539027] - 27/04/20 - $500
Blind injection vulnerability inside a temporary logging system.

Anonymous - 04/07/20 - $1,500
Serious vulnerability allowing the take over an account with 2FA disabled using the email validation system.

Anonymous - 06/07/20 - $500
Ability to retrieve a message's subject via its ID (up to once every 10 - 60 seconds) by manipulating POST input.

booboo001 [2582543] - 08/07/20 - $2,500
Three separate injection vulnerabilities on Tutorials system, Mobile app end point, and email verification.

Anonymous - 09/07/20 - $500
XSS exploit with CSP bypass via google domains.

booboo001 [2582543] - 14/07/20 - $2,500
Another selection of various injection vulnerabilities.

booboo001 [2582543] - 20/07/20 - $1,000
Two blind injection vulnerabilities in the casino.

booboo001 [2582543] - 31/07/20 - $1,500
Three blind injection vulnerabilities.

Anonymous - 03/08/20 - $1,000
Item duplication vulnerability.

booboo001 [2582543] - 24/08/20 - $1,000
Two blind injection vulnerabilities.

Juggernaut-XMeN [1898201] - 30/09/20 - $500
A blind injection vulnerability.

booboo001 [2582543] - 21/10/20 - $500
A blind injection vulnerability.

AldenIsMe [2538462] - 05/11/20 - $1,000
Exploit allowing the use of another player's item from their inventory.

booboo001 [2582543] - 17/12/20 - $500
A blind injection vulnerability.

mgthura [1898201] - 31/10/21 - $1,000
A blind injection vulnerability with Bookies 2.1.

user [2088243] - 06/12/21 - $1,000
App login system's potential vulnerability to a brute force attack.

APT [2538462] - 17/01/22 - $500
Ability to create multiple loadouts beyond the in-game capacity (discretional reward).

Lugburz [2386297] - 24/01/22 - $3,000
A significant chat vulnerability and status panel disclosing exact travel time.

Bacurau [2245633] - 10/02/22 - $500
Discretionary reward for a specific BBCode exploit that crashed browsers.

Lugburz [2386297] - 10/02/22 - $1,000
Unintended data leak involving hidden information about one's own account.

Bug [1455582] - 11/02/22 - $1,000
Limited blind injection possible on an ajax request.

Anonymous - 19/02/22 - $500
Discretionary reward for pointing out inferior rate limiting when checking email addresses on Account Recovery.

MrAdequate [2616736] - 03/03/22 - $500
Discretionary reward for alerting us of incorrect Russian Ruble rates on donator page allowing cheap DPs.

Bug [1455582] - 27/06/22 - $1,000
Vulnerability allowing the sending of app push notifications with custom text to other users.

Lugburz [2386297] - 19/07/22 - $1,000
Insufficiently protected legacy authentication method which had no captcha after failed requests.

Bug [1455582] - 15/07/22 - $1,000
Found method of bypassing the 'wrong password' captcha on one of our internal authentication systems.

Lugburz [2386297] - 23/08/22 - $500
Discretionary reward for finding and reporting on abuse involving slow-loading / session-locking searches.

Bug [1455582] - 23/09/22 - $1,000
Discovery of an XSS vulnerability on the system that handles discord name & status verification.

Anonymous - 14/10/22 - $500
Discretionary reward for the report of a CSRF exploit which could switch another player's loadout.

Anonymous - 23/10/22 - $2,500
Item creation / duplication by manipulating request data during Bazaar item removal (logs found no exploiters).

Anonymous - 09/11/22 - $2,500
Vulnerability on pre-validation email change allowing possibility of changing user's email with CSRF attack.

Anonymous - 09/11/22 - $750
Various CSRF related vulnerabilities.

Anonymous - 06/02/23 - $2,500
Ability to bypass login rate limit from a single IP.

mgthura [1898201] - 26/04/23 - $500
A CSRF exploit potentially allowing a player to be joined to an RR game or make a bookie bet without consent.

Anonymous - 16/05/23 - $500
Discretionary reward for the discovery of a vulnerability allowing limited Google authentication bypass.

Anonymous - 03/07/23 - $500
Discretionary reward issued for discovery of forum vulnerabilities in IMG tags requiring additional sanitization.

Bryan [2561900] - 29/08/23 - $2,500

Duplication of money through Poker Tournaments.

Anonymous - 29/08/23 - $1,000
Exploit allowing bypassing of rate limit of accounts using Authenticator 2FA allowing for brute force decryption attacks.

mgthura [1898201] - 07/12/23 - $2,500
Report involving numerous chat 2.0 vulnerabilities, including name spoofing and administrative access for civilians.

Frodo [2282199]- 15/12/23 - $500
Discretionary reward following research and recommendations into additional security improvements for the security panel.

zloi [2655608] - 12/01/24 - $2,500
Item duplication via Crimes 2.0 (Cracking)

martianmellow12 [1992729] - 08/04/24 - $1,000
Ability to join races using unowned cars, including other players' cars.

mgthura [1898201] - 29/04/24 - $1,000
Ability to invite themselves into other player's P2P chats with potential impersonation implications.

 

Anonymous - 18/07/24 - $500

Reported issue of uncontrolled resource consumption vulnerability in chat.

 

Anonymous - 28/08/24 - $1,000

Reported exploit in S3 buckets with incorrectly configured DNS entries.

 

Anonymous - 11/10/24 - $500

Reported CSRF exploit in the Points Building.

 

mgthura [1898201] - 11/10/24 - $500

Discretionary reward issued for CSRF exploit which could purchase other point building objects for other players.

 

Frodo [2282199]- 16/10/24 - $500
Discretionary reward for reporting an exploit allowing private thread titles to be shown. 

Dazzles [2745519] - 26/10/24 - $500
Discretionary reward for reporting a CSRF in item market 2.0. 

Lordskeleton [2512774] - 26/10/24 - $1,000
Reward for reporting a vulnerability allowing purchase of negative goods, potentially resulting in illicit cash transfers. 

 

Batman [984129] - 05/11/24 - $2,500

Reward issued following report of item duplication involving dirty bombs in Item Market 2.0

 

Anonymous - 13/11/24 - $2,500

Report of item duplication in item market 2.0

 

Bacurau [2245633] - 10/02/25 - $500

Discretional payment for accessing other account mail subjects, limited scope.

 

Bacurau [2245633] - 10/02/25 - $10,000

Reward issued following report of critical level SQL injection with the potential for read/write database access. 

 

Kwack [2190604] - 02/06/25 - $500

Reward issued following report of unauthorized access to static files in dev environment.

 

Anonymous - 09/06/25 - $500

Reward issued following report of job special usage outside of job. 

 

dawdad [3725299] - 13/06/25 - $500

Reward issued following report of unauthorized acceptance of faction applications

 

Anonymous - 03/07/25 - $500

Discretional reward issued following report of numerous low impact CSRF vulnerabilities

 

dawdad [3725299] - 17/07/25 - $1,000

Reward issued following report of being able to steal/destroy loaned faction items through unauthorized means which would have resulted in significant staff time resolving

 

dawdad [3725299] - 17/07/25 - $2,500

Reward issued following report of leaked Torn system credentials in the codebase, no access was possible, however presented significant potential risks

 

dawdad [3725299] - 09/09/25 - $500

Discretional reward issued due to additional methods elating to previous bugs for destroying faction items through unauthorized means

 

tiksan [2383326] - 09/09/25 - $1,000

Bug bounty issued following disclosure of Sendbird Admin API hard coded into published Android app.  

 

Stig [2648238] - 19/09/25 - $500

Discretional bounty issued following disclosure of higher access data in public API

 

mgthura [1898201] - 07/10/25 - $1,000

Bounty issued following limited disclosure of active messages

 

dawdad [3725299] + Bacurau [2245633]  - 14/10/25 - $500 + $500

Bounty issued following disclosure of limited access to development environment

 

Frodo [2282199] - 16/10/25 - $500

Discretional bug bounty issued following disclosure of limited security vulnerability involving sourcemaps.

 

Anonymous - 26/11/25 - $500

Discretional bug bounty issued following disclosure of limited issue allowing for unexpected item usages in Arson crime.

 

Mauk [1494436] - 01/12/25 - $500

Discretional bounty issued following disclosure of CSP issues and bugs caused by unsanitized inputs

 

Anonymous - 07/01/26 - $500

Discretional bug bounty issued following disclosure of CSRF vulnerabilities involving Torn casino games.

 

CockyNudist [2209950] - 12/03/26 - $500

Discretional bounty issued following disclosure of guaranteed success exploit in scamming crime

 

dawdad [3725299] - 17/04/26 - $1,000

Bounty issued following disclosure of limited but legitimate IDOR vulnerability within poker

 

mgthura [1898201] - 07/05/26 - $1,000

Bug bounties for multiple reports bypassing limited security settings within app

 

mgthura [1898201] - 19/05/25 - $1,250

Bug bounties for multiple reports within the Android app manipulating other user notifications

 

highlight [2123910] - 21/05/26 - $1,000

Bug bounty awarded for disclosure of limited exploit in High-Low revealing possible upcoming hands.

 

Anonymous - 02/06/26 - $500

Discretional bug bounty for report on certain in game company positions not reflecting correct
efficiency values.

 

Eldlyn [2629453] - 08/07/26 - $2,500
Bug bounty issued following report of item duplication involving display case and travel 2.0 inventory

 

MikePence [2029670] - 27/07/26 - $500 + $500

2 x discretional bug bounties for CSRF vulnerability involving cashier checks and unsecured ability to adjust faction perks without required permission

 

Hexly [3268572] - 27/07/26 - $2,500

High tier bug bounty awarded following disclosure of exploit allowing acquisition of any user's inventory with potential concerns for item duping

 

highlight [2123910] - 12/08/26 - $500

Discretional bounty awarded following report of cache poisoning leading to same-origin session XSS

 

LtCabel [2897639] - 17/08/26 - $500

Discretional bounty awarded following report of unintentional issue with TGP stock benefits remaining active after sale

Mentions: APT [2538462] · Bacurau [2245633] · Batman [984129] · booboo001 [2582543] · Bryan [2561900] · Bug [1455582] · CockyNudist [2209950] · dawdad [3725299] · Dazzles [2745519] · Eldlyn [2629453] · Frodo [2282199] · Hexly [3268572] · highlight [2123910] · Kwack [2190604] · Lordskeleton [2512774] · LtCabel [2897639] · Lugburz [2386297] · martianmellow12 [1992729] · Mauk [1494436] · mgthura [1898201] · MikePence [2029670] · nostarch887 [2539027] · Shane [1514924] · Stig [2648238] · tiksan [2383326] · zloi [2655608]