Cool Tabs takes the security as a top priority. We are committed to ensuring your protection and privacy.
This vulnerability disclosure policy, which must be read in the context of the Cool Tabs Terms and Conditions, is intended for security researchers interested in reporting security vulnerabilities to Cool Tabs, and is intended to provide guidelines on how to responsibly report vulnerabilities to Cool Tabs.
If you believe you have discovered a vulnerability, that may compromise the confidentiality, integrity, or availability of a Cool Tabs site or application and the information handled therein, we urge you to report it to us as quickly as possible and not publicly disclose the vulnerability until it is fixed.
To encourage responsible disclosure, Cool Tabs will not take legal action in connection with your vulnerability detection activities on our systems, as long as you follow the guidelines in this policy.
Responsible Disclosure Guidelines
- Notify Cool Tabs and provide us details of the vulnerability. Please provide us a reasonable time period to address the issue before public disclosure.
- Provide an appropriate level of detail on the vulnerability to allow us to identify and reproduce the issue. Detail should include target URLs, request/response pairs, screenshots, and/or other information.
- We will confirm your email and evaluate the validity and reproducibility of the issue. For valid issues, we will work to fix the issue and keep you appraised of progress.
- Make a reasonable effort to avoid service disruption (e.g. DoS), privacy issues (i.e. accessing a Cool Tabs user’s data), and data destruction when performing vulnerability research.
- Do not request compensation for security vulnerability reports either from Cool Tabs or external vulnerability marketplaces.
- Do not phish or social engineer employees, partners, or users of Cool Tabs.
- Do not run automated scanning tools and send us the output without confirming the issue is present. Security tools often output false positives that should be confirmed by the reporter.
Vulnerability Categories We Encourage
We are primarily interested in hearing about the following vulnerability categories:
- Cross Site Scripting (XSS)
- Cross Site Request Forgery (CSRF)
- SQL Injection (SQLi)
- Authentication related issues
- Authorization related issues
- Data Exposure
- Redirection Attacks
- Remote Code Execution
- Particularly clever vulnerabilities or unique issues that do not fall into explicit categories
Out of Scope Vulnerability Categories
The following vulnerability categories are considered out of scope of our responsible disclosure program and will not be eligible for credit on our researcher list:
- DMARC, SPF records configuration
- SSL vulnerabilities related to configuration or version
- Denial of Service (DoS)
- User enumeration
- Brute forcing
- Secure flag not set on non-sensitive cookies
- HTTPOnly flag not set on non-sensitive cookies
- Logout Cross Site Request Forgery (CSRF)
- Issues only present in old browsers/old plugins
- HTTP TRACE method enabled
- Vulnerability reports related to the reported version numbers of web servers, services, or frameworks
- Clickjacking on pages without authentication and/or sensitive state changes
- Vulnerability reports that require a large amount of user cooperation to perform unlikely or unreasonable actions which would be more symptomatic of a social engineering or phishing attack and not an application vulnerability (e.g. disabling browser security features, sending the attacker critical information to complete the attack, guiding the user through a particular flow and requiring them to enter malicious code themselves, etc.)
How to Report a Security Vulnerability
Please email help@cool-tabs.com to report security vulnerabilities to Cool Tabs. If you feel the email should be encrypted, our PGP key is available here:
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQENBFBcjLkBCACVprcIWOSqiyPj3gLeeJxH4T6jWzwxpCLNgYZoKjdA7B4B35M/
AySeNTairYdiOsEs+g8JdLi8G1SyOziZ4w8lHUfIMObzm1YXoWmaaCcMW+kq9jQ3
JTFc43HeFS9sljMW76jFeSg7LuLteHKv/ZHe314CEBKWmczIagoteS4+ry5Adp3Y
X1F3GVf6vsRtjQ4x651/0SKUxsZwwZW8trsCydv89fwSYohEQfJBstlg9WYmfhSD
1HeTpaKa9QZndjiGMFZq4Dv78irzQIVAGY4effTZvkxP8sFllitj9ETGu3SfG0a0
qGD0fOkVm6RreGOwL4PdkBnpfDyU5g4YZpc9ABEBAAG0JUFkbWluIENvb2wgVGFi
cyA8YWRtaW5AY29vbC10YWJzLmNvbT6JATgEEwECACIFAlBcjLkCGwMGCwkIBwMC
BhUIAgkKCwQWAgMBAh4BAheAAAoJEGZT+nH+tbAOoTwH/0L4lTWeDblyprOeD04u
+ppFPHL/wdke/K/YVTY8Bl3ZRSH/D2wASQGwXpghnEjhKrcmagCEcOxo7I06dNG1
jX9/3/jBcqAk5EWr5Oxb8a+AT+5qcJTfSgt7artJ+BT44NZUYtMZDeBNv04dPRms
XtVijpSusAcEzb/m4BEymIPzsWE1KRJvnThgsVMG+Iugt8QHouFJalp9P6mErvc/
VQFw4duDoTS5WLRLBvkE2qYVqSs2GSCnRIW53Xperjup9Oo/7Jqptx+JVolNbnb8
tml+wuQS+1XIlq7yK9WTGnZTITVOCnEQlU3zyFIdItmsBKEm+uVsudVXr8XbExKX
2o6JAhwEEAECAAYFAlURJq8ACgkQ6HykuKJdPhwAdg/+JSd4iEvVsygQnTo+YRR5
MhEYGFnzRB6SKv2BpRRTLeDaWVMuf3OtuPx1WANQQzAS2Etw1cvRPy4AVL4G7wpu
72XGOaOeDhukYti+f2Evg13UK9n0BUG41gl/UeiUV4pkWAqEZUxRauNn1/Jx+P9K
IlA9dXgwReW3iGO0AsNANRtuGU3liyx1MkE3tkWTjkawu88TEi/8CdjU7EHQs6nR
HJb7KxQkPDQkqkvJfZI8neY0wVoIqBwAIwfH8vYShn+Noti3R4RUoVkxDckifpRK
CZG2EgegWT5DJI5cFzxMSrdR6shQZr/7lGOxWeaG4AoDVxWLNTXZTAB0nXuffOcj
L8/tr8GHoiyHPXr1wHZgmDdVU1W33uxa3MO6R/QniIBAGVYP+HO9xPDqZI/OoVXD
VJb7rvuw6sQXOMSFep6+8rOwQR/TYiysKCdcvAf0C0DK0bUutrOF9TO0ZOAQ5aAL
Fo69nK0rjT/IyeJW0zTx8nziAd5FpTqjdwgo2qF0zcj634UikRplzmcEWzEeUQHV
lxkIElhPboSGlbXEo6H3zm181uQNwVQySQXEXxMWfk1+vZLDD/COMThpdYGMmKfU
RxCoKOgQYAKuALFaAgfVOTjqU+BzXK41knQK6p91oUovR24GGtkvwqEXHrq7I+hf
9Hk+IDASP73h4T2fqXLNapu5AQ0EUFyMuQEIAOQ1WoQHBoluMSdzY4njU8eFHhfi
mYxfWKzZQVbSky3PBUtlumAc8XSAHsRKocbsbyH07wkqpEIb2kk+ZA3uxD23uktq
YDyroatFfYQ3GS6vJet/V4SLlliurmgyXSDvGjdg99O1yDcJyKCvAzZZpaGVJhYK
ylzFIlwJmr6+2gj6RcvdCMSOjlwuoOMNFfrv7NqJCNn/9t3rgHYgacipzuVM7zbb
l8RgHaTuJu0qtaI87R8Zyw3tEq6EHUJr2xLgxfKUNhCUmacaEy5q9BOnZqQvBqlk
SAiEGJtG/dS+cw7TqP+FvoCB34rNssIjvvtc85njuUdHuHNatVWuos3cnlUAEQEA
AYkBHwQYAQIACQUCUFyMuQIbDAAKCRBmU/px/rWwDtjGB/4uF2gJaw+8HJBznrDa
1PhVcTaCPNd2b8sAVMPop06zFZQMd13jXxLepm7uwunDhD+yD28eeeollUHC3hKZ
FjVr3D151867MrjRa6HzugEfKT1tkXMdT7CzDZf/rs8LI15E0bH0nxYrX5B5xfV5
M0KpjozL8Iu7bPJoTHbzoD9APKPg0ExoNy/O/a5cPBaVxK5oHoQ9giOWd/WsN/c/
aepwU/Etgjc0uDHS7Y2TRoWwCKRZrLeOS7bRkxYQUUi2kLP8sI1zoqUBn5bY0Usz
/OekJU3opUitQ2ytvdDT85lQq5c9OK5sPbHHz6Yl7mWAqbLaQB9aeeNjUQKFIQvr
xk/w
=KINq
-----END PGP PUBLIC KEY BLOCK-----