What this is
This is a small bug bounty program and we run it ourselves. No platform sits in between. You email us, a volunteer reads it, and we sort it out from there.
The rewards won't change anyone's life. They come out of the same pot that prints our booklets and pays the mirror's bandwidth bill, so they're modest by necessity rather than by choice. What we can promise is that the money is real, the timelines below are ones we keep, and a person will write back to you.
We opened this program on Software Freedom Day, 21 September 2024. Scope and rewards have shifted four times since then, and the changelog has all of it.
What is in scope
Six things. Anything outside this list falls outside the program, though we'd still like to know about it.
- Infrastructure
mirror.thepenguins.clubup to ৳5,000The Debian/Arch/Ubuntu package mirror. Anything that lets you serve modified packages to students is the worst day we can have, so treat it as the crown jewel.
- Running bot + source
uradhuraup to ৳5,000The Rust bot that runs in our groups. Command injection, privilege confusion between admins and members, token leakage: all of it counts.
- Containers on our public host
Self-hosted community servicesup to ৳5,000One Linux box runs most of what we operate as Docker containers behind a reverse proxy — the status page, self-hosted Git, workshop pads, meeting rooms, metrics. If it has a port open on that machine it counts, whether or not we remembered to name it here.
- Web — static site
thepenguins.clubup to ৳1,000This site, including /events, the generated .ics feeds, and the blog. It's a static Astro build, so the interesting findings tend to sit in the build pipeline rather than at runtime.
- Source code
github.com/the-penguins-club/*up to ৳2,500Public repositories. Leaked credentials in history, workflow injection in GitHub Actions, and anything that lets a non-member push to main.
- Build-time data flow
Community event pipelineup to ৳2,500Issues in the the-penguins-club/events repo are parsed into pages at build time. What matters here is what a crafted issue body does to the build host and the deploy that follows — not what it renders.
One deliberate quirk worth knowing
Our content admin at /keystatic only loads while the dev server is running, and never gets built into production. That's deliberate, because it has no authentication on it at all. If you ever find it reachable on the live site, that's a valid High and we'd very much like that email.
Explicitly out of scope
- Anything run by a third party we simply use: GitHub, Telegram, Discord, Google Fonts, the registrar. Those go to them.
- Our partners' and members' own sites, even if we link to them.
- Denial of service, volumetric testing, or anything that degrades the mirror for students who are mid-download.
- Social engineering of volunteers, phishing, or physical access attempts at a meetup venue.
- Automated scanner output pasted without a working proof of concept.
Rewards
Paid in Bangladeshi Taka. We pick the band, but we'll show our working, and you're welcome to argue. More than once we've moved a report up after the reporter made a better case than ours.
| Severity | Reward | What it means |
|---|---|---|
| Critical | ৳5,000 | You can run code on our infrastructure, serve modified packages from the mirror, or take over the GitHub organisation. For example: Container escape or unauthenticated RCE on the host we run everything from; pushing an arbitrary package the mirror's clients accept. |
| High | ৳2,500 | You can read data you shouldn't, or act with privileges you don't have. For example: A published container port that bypasses the host firewall; a leaked deploy token with write access; the bot running a privileged command for an ordinary group member. |
| Medium | ৳1,000 | A real vulnerability that needs a precondition, user interaction, or a chain to become serious. For example: The apt sources snippet we hand out at install-fests shipped without a signed-by pin, leaving students on hostile campus Wi-Fi open to package tampering. |
| Low | ৳500 | Real and verified, but small in reach. Worth fixing, and worth paying for. For example: An information leak that narrows an attack without enabling one. |
| Informative | Swag + credit | Not a vulnerability, though it taught us something or tightened a rough edge. For example: A sticker pack, a printed booklet, and your name in the Hall of Thanks if you want it there. |
How payment actually works
- One reward per root cause. Five symptoms of the same bug is still one bug, and we'll explain why we've counted it that way.
- The first reproducible report gets the reward. Duplicates get credit, and we'll tell you when the original came in.
- Paid within 30 days of us accepting the report, once you've sent payment details. There's no invoice to raise and nothing to sign.
- Any tax owed on the reward is yours to handle, wherever you live.
- Volunteers who help run our infrastructure can't claim rewards on the things they maintain. They still get credit.
We can pay by
Whichever suits you. Tell us when we accept the report. We won't push you towards one method or ask for more detail than that method needs.
- bKash or Nagad (inside Bangladesh)
- Bank transfer (inside Bangladesh)
- Wise or PayPal (outside Bangladesh)
- Donate it onward; it goes to the booklet printing fund and we say so publicly
How to report
Email security@thepenguins.club. That's the whole process. If three working days go by with no reply, nudge admin@thepenguins.club. Something will have gone wrong at our end, and we'd rather you chased us.
PGP, if you want it
If it's sensitive, encrypt it with our public key.
4D41 7921 8379 FC31 9652 382E F4BE 5A98 3F17 2316
What to put in the email
- Which asset. One of the six above, by name.
- What you did. Enough for us to reproduce it: a request, a script, the clicks you made and the order you made them in.
- What happened. The output or behaviour you saw, rather than what you concluded from it.
- Why it matters. What an attacker walks away with. This is the part that decides the band, so give it a couple of careful sentences.
- How you'd like to be credited. A handle, your name, a link, or nothing.
English or Bangla, whichever you'd rather. Neither will slow your report down.
What happens next
Targets rather than guarantees. We publish them because researchers kept telling us the silence was the worst part of reporting to a small project.
First reply
3 working daysSomeone reads it and writes back to say it arrived.
Triage decision
10 working daysWe tell you whether we could reproduce it and which band we think it lands in.
Reward decision
15 working daysThe final band and the amount, with our reasoning. Argue if you disagree.
Payout
30 days from acceptanceSent once you've given us payment details.
Fix deployed
90 days targetUsually much sooner. If something's going to drag, we'll tell you why and keep you posted.
Rules of engagement
Please do
- Test only the assets in scope, using your own accounts and your own data.
- Stop once you've proved the issue. Pulling one record proves it; pulling a thousand is a breach of its own.
- Write it up clearly: what you did, what happened, why it matters. A screenshot and a short script will get you further than an essay.
- Report each distinct root cause separately.
- Give us 90 days before you publish, and let us know when you're planning to.
Please don't
- Don't access, change, download or keep anyone else's data. If you stumble into personal data, stop there and say so in the report.
- Don't degrade the service. Students pull from the mirror on slow connections, so brute force and load testing are off the table.
- Don't leave anything behind. No web shells, no planted accounts, no backdoors. Clean up after yourself, or tell us what needs cleaning.
- Don't push disclosure deadlines shorter than 90 days at us, and don't offer to sit on a report for money. That's extortion, and we'll treat it as such.
- Don't test the venue, the volunteers, or anyone's personal devices.
Safe harbour
Follow the rules above, act in good faith, and give us a fair chance to fix what you found, and we'll treat your research as authorised. We won't take legal action against you. We won't report you to anyone. And if someone else comes after you over research you did inside this scope, we'll say publicly and in writing that you had our permission.
Bear in mind who's making that promise. We're volunteers, and we can't speak for our hosting providers or anyone else whose terms you might cross. Stay inside our scope; that's as far as our word reaches.
Act in bad faith and none of it applies. By that we mean extortion, data theft, deliberate damage, or dragging someone else into it.
Things we already know
These come up constantly and don't earn a reward on their own. Chain one into something real and it's a different conversation; we'll pay for the chain.
- Missing security headers (CSP, HSTS, X-Frame-Options) on the static site, with no demonstrated exploit.
- Missing SPF/DKIM/DMARC records, unless you can show a deliverable spoofed mail.
- Clickjacking on pages with no state-changing action, which is every page we have.
- Self-XSS, or anything requiring the victim to paste code into a console.
- Rate limiting on a static site served from a CDN.
- Outdated library versions with no exploit path in the way we use them.
- Open redirects that don't cross a trust boundary.
- Best-practice notes that aren't vulnerabilities. We'll read them; they just aren't bounties.
Disclosure
Coordinated, and we lean towards publishing. Wait for the fix to ship or for 90 days to pass, whichever lands first, then write it up wherever you like. Tell us the date so we aren't caught out, and if you'd like us to check the technical details beforehand, just ask.
Good write-ups help everyone, including the next community that inherits the same mistake. Send us the link when yours goes up and we'll put it beside your name below.
Hall of thanks
People who made this safer for everyone else, newest first. Some reporters asked to stay anonymous, so this list runs shorter than the number of reports we've closed.
- @sabbirHardening notes for the reverse proxy's TLS config and HSTS preloadInformative
- @n0shinDocker socket bind-mounted into the public status-page containerCritical
- @mehjabinCompose bind-mount served the project .env through the reverse proxyHigh
- @tanvir-secReverse-proxy dashboard reachable without auth, listing every internal routeMedium
- @arnab.kPublished container port bypassed the host firewall, exposing RedisHigh
- @sabbirContainers ran as root with the host home directory bind-mountedLow
- @faria.rSelf-hosted Git instance had open registration and world-readable internal wikisMedium
- @shuvoBot honoured admin commands from a departed memberHigh
- @aurnobnode_exporter published to the internet, leaking host inventoryLow
- @n0shinDeploy token readable in a public workflow logHigh
- @aurnobStale subdomain pointing at an unclaimed hostMedium
- @ruhanEvents .ics feed exposed a venue address for an unannounced meetupLow
- @tanvir-secMirror's published sources.list snippet omitted the signed-by pinMedium
- @sadiaMalformed DMARC record on the club domainInformative
- @rifat.hMirror rsync module exposed a writable pathCritical
Rules changelog
Scope and rewards shift over time. We judge every report against the rules as they stood on the day you sent it.
Raised the Critical band to ৳5,000 — which is as far as the fund stretches without eating into the booklet budget.
Brought the container host and the event pipeline into scope, having spent a year pretending the box was somebody else's problem.
Added the uradhura bot to scope. Clarified that duplicate reports still get public credit.
Published explicit response targets after researchers told us the silence was the worst part.
Program opened on Software Freedom Day with the mirror and this website in scope, funded from the community fund.
Questions we get asked
Why is the money so small?
Because we're volunteers, and the bounty fund is the same one that prints booklets and pays for the mirror's bandwidth. We'd sooner pay a small amount on time, every time, than advertise a figure we can't honour.
Do I need to be in Bangladesh?
No. Anyone can report, and we pay internationally through Wise or PayPal. The infrastructure serves students here; whoever helps protect it can be anywhere.
What if someone already reported it?
The first reproducible report gets the money. Duplicates still get credit in the Hall of Thanks if you want it, and we'll tell you straight when the original came in.
Can I publish my write-up?
Yes, please do. Give us 90 days or wait for the fix, whichever comes first, and tell us when you're posting. Happy to check it over for accuracy first if that's useful.
Is there a leaderboard or points system?
No. We're far too small for it to mean anything, and a handful of reports a year doesn't need a scoreboard.
I found something in a member's personal project.
Out of scope for us, but tell us anyway and we'll put you in touch with the maintainer. There's no bounty on it. We'll still thank you properly.