Mobile Proxy Zone logo
Security

Responsible disclosure & bug bounty policy

We want to be told about any vulnerability you find in Mobile Proxy Zone. On this page: what is in scope, what we pay for, what we don't pay for, and how to report, so there are no surprises either way.

Scope

In scope

  • This website, mobileproxyzone.com
  • The customer dashboard you log in to and the API it exposes
  • Rotation links, API keys and proxy credentials, as the dashboard handles them

Out of scope

  • Modem hosts, proxy gateways, and the mobile carrier networks they connect through
  • Payment processors, Telegram, Cloudflare and email providers (third-party services)
  • Marketing assets served from legacy CDN paths
  • Any customer's account or data, unless it is yours

What we pay

To earn a reward, demonstrate impact on our systems or our customers. Amounts are in USD.

Critical
$100 – $250
  • Remote code execution on our servers
  • SQL injection that pulls or writes customer data
  • Any-account access with no credentials, through an authentication bypass
  • Proxies, credit or refunds without paying, by manipulating payments or balances
  • Personal data or proxy credentials of other customers, exposed in bulk
High
$50 – $100
  • Reading or changing a fellow customer's proxies, orders or account details (IDOR)
  • Stored cross-site scripting that ends up running in another customer's or admin's session
  • Using privilege escalation to go from a customer account to admin functions
  • Server-side request forgery reaching internal services
  • Making off with another account's API key, rotation link or session
Medium
$20 – $50
  • Cross-site request forgery against an account action that changes state
  • Reflected cross-site scripting that needs a victim's click on a link
  • Account takeover, demonstrated, through a rate-limit bypass
  • Business-logic or pricing errors where you demonstrate the financial impact
Low / Informational
$0

They're acknowledged and fixed where warranted, not paid. The full list sits below, so you can check it before you write the report.

What we do not pay for

These get accepted as Low or Informational, at the very most. We read them and take care of what is worth fixing, but no bounty is issued, and a Critical or High label on the report will not change that.

  • A session that outlives a logout, a password reset or a password change, lasting until token expiry
  • Security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) missing or “weak” where no working exploit exists
  • Clickjacking of a page offering no sensitive action
  • How attributes are set on cookies that are not session cookies
  • Email or username enumeration, error messages and timing included
  • Observations on login, rate limits or forgot-password with no account takeover demonstrated
  • Takes on password policy: length, complexity, common-password lists, no forced rotation
  • Two-factor authentication absent, or 2FA set as optional
  • XSS that the attacker can only trigger in their own session (Self-XSS)
  • CSRF on a login, logout, language or other non-sensitive form
  • Open redirects, unless they leak a token or credential
  • Disclosure of software versions, server banners, stack traces or paths lacking sensitive data
  • SPF, DKIM or DMARC configuration reports
  • Whatever an automated scanner outputs, without a proof of concept
  • Denial-of-service and resource-exhaustion tests, brute force, or any test that creates load
  • Physical attacks; social engineering or phishing of our customers or staff
  • Issues with any third party we use: payment processors, Telegram, Cloudflare, email providers
  • Libraries on outdated versions with no working exploit against our deployment
  • Attacks relying on a rooted phone, a compromised device or being man-in-the-middle
  • Best-practice notes, theoretical risks and duplicates of issues already known

How to report

Email [email protected] with the subject Security report. Make sure it has the affected URL, exact steps to reproduce, the account you used and a proof of concept. An acknowledgment arrives within 5 business days, and a decision on severity within 10 business days.

Machine-readable contact details are at /.well-known/security.txt.

Send a report

Policy last updated 2026-10-10.

Rules of engagement

  1. First valid report wins. Duplicates and reports covering issues we already know about are unpaid. Multiple affected endpoints with the same root cause still mean one payment.
  2. Prove it, then stop. Access only your own accounts and data. Stop at the first proof and report whenever a test would expose someone else's data — no pivots, downloads or persistence.
  3. Do not degrade the service. Proxy gateways, modem hosts and carrier networks are not to be tested, and neither load testing nor automated fuzzing at volume is allowed. Those are out of scope entirely.
  4. Give us time. Don't publish until the fix is done and 30 days have gone past. We will confirm to you when a fix is live.
  5. Severity is ours to set. We look at impact on our own systems and rate it with the Bugcrowd Vulnerability Rating Taxonomy as the reference. Payment is by PayPal or USDT, and the amount is at our discretion within the ranges above.
Safe harbour. Research that follows these rules is authorised. Stay within scope and test in good faith, and we will not pursue legal action against you; we ask that you extend the same good faith to us: no extortion, no threats of disclosure, no “pay first, details later”.