http://agoradesk.i2p/nojs/security-bounty-whitehat?dismissNotice=true
In order to encourage responsible disclosure, we promise not to bring legal action against researchers who point out a problem provided they do their best to follow the above guidelines. Eligibility In general, anything which has the potential for financial loss or data breach is of sufficient severity is eligible, including: • XSS • CSRF • Authentication bypass or privilege escalation • Click jacking • Remote code execution • Obtaining user information • Accounting errors In general, the...