TryHackMe both encourages and rewards responsible security bug discovering and disclosing. Whilst we review every report on a case-by-case basis, we ask for you to follow a few rules to ensure your bug qualifies.
Please note that these are subject to change at any time, and should act as guidance. Disclosed issues may still be rejected even if it adheres to the below.
- Adhere to the TryHackMe Terms and Conditions at all times.
- No mass-or-automated scanning tools. These will quickly be blocked by Cloudflare at the very least.
- Do not affect or attack other users. You can create another profile as a proof of concept, but do not affect other user's experience of TryHackMe, including any instances deployed by them.
- Do not abuse the bug you have discovered. For example, abusing a way to gain more points which places you first place on the Monthly leaderboard.
- Do not discuss the bug outside of the disclosure process to TryHackMe
I think I've found a Bug!
We'd love to hear about it. Again, every report is reviewed on a case-by-case basis. Please email [email protected] including the following details:
- Type of vulnerability
- Detailed steps to reproduce
- Scope of what is affected by the vulnerability
- Your TryHackMe username
TryHackMe rewards valid and responsibly disclosed bugs through a variety of means, again, on a case-by-case basis including:
- Bug Hunter Title (awarded after 3 valid bugs have been found)
- VIP Vouchers