We may not realize it, but almost every action we take is tied in some way to digital information and its management. In our role as creators of the systems and programs of the University of Economics - Varna, we from the team of CRANICT strive to create another facilitation or optimization. But accustomed to human imperfection, we can inadvertently miss a check or part of an algorithm that exposes personal data to external attacks. The goal of this program is to create a quick channel where anyone can put on their white hacker hat and tell us how to make UE-Varna's systems more secure. We want to know if the protection of our sites is strong enough and if a malicious user can access information that could harm us. If you think computer security is your strength, see how you can win a prize by helping us find a potential vulnerability.
While every single system is important to us, finding security holes on the following university platforms is a priority for now:
Exposure of sensitive data - Cross Site Scripting (XSS), SQL injections, etc.
Vulnerabilities related to authentication or session management;
Execution of code on a server (Remote Code Execution).
Another type of vulnerabilities that do not correspond to the above categories, but nevertheless pose a risk to the personal data of the users of the systems.
Problematic configurations or application logics that may lead to sensitive data leakage.
Not to perform DoS or DDoS attacks on systems.
Not to use techniques such as phishing, vishing and similar.
Users of the systems should not be subject to attack in any way.
Do not distribute sensitive data.
If a bug is discovered, do not abuse the data you could access (eg extract additional data, modify or delete).
Do not disclose information about the bug to third parties until we fix it.
This site is protected by reCAPTCHA