comps.gg/security
·
responsible disclosure
← comps.gg
# Security & Responsible Disclosure
Last updated: 2026-07-21 · Contact: [email protected] · Test target: demo.comps.gg
Report something real and in scope and we'll fix it fast, credit you, and pay cash for the serious stuff. No legal games — see Safe harbour.
## What's actually worth your time
These are the crown jewels. A working PoC against any of them is high severity and paid as such. Aim here, not at missing headers.
- Extracting real cash — turning site credit into withdrawable money you weren't owed, or moving funds between accounts.
- Paying less than the price — underpaying or paying nothing at checkout. Discount stacking, price tampering, basket manipulation.
- Peeking an outcome — learning a draw or instant-win result before you commit to pay, then bailing if you lost.
- Acting as someone else — reading or changing another account's tickets, orders, wallet or personal data. Auth / ownership bypass.
## Rewards
Fixed bands, paid in cash via PayPal. First valid report on an issue wins; dupes and known issues pay nothing. Final severity is ours to call, and we'll show our working — set by what you actually demonstrated on demo.comps.gg, not by the CVSS score, CWE list or ASVS clause you attach. A wall of references doesn't raise a finding; a working PoC does.
| Severity | Looks like | Reward |
| P1 · critical |
cash extraction, auth bypass, pre-pay outcome peeking, full account takeover |
£500–£1,000cash |
| P2 · high |
underpaying at checkout, reading another user's private data, stored XSS in an authed area |
£150–£300cash |
| P3 · medium |
lower-impact logic flaws, limited info disclosure, CSRF on a meaningful action |
£50–£100cash + credit on the wall |
| P4 · low/info |
best-practice findings with no demonstrated impact |
—hall of fame at our discretion, for findings we act on |
## Scope
### In scope — test here
demo.comps.gg and api-demo.comps.gg — our dedicated test environment
- auth, checkout, wallet, discounts, referrals and draw logic on that target
- logic flaws that let you underpay, double-claim, replay, or see hidden outcomes early
- anything under "what's actually worth your time"
### Out of scope — don't
- live operator production sites — report suspected issues, do not exploit them
- DoS, volumetric / load testing, brute force
- missing headers, SPF / DMARC / DNSSEC, cookie flags with no demonstrated impact
- self-XSS, clickjacking on pages with no sensitive action, tabnabbing
- scanner output with no working PoC
- session lifetime against your own account — "it still works after I log out / reset my password" with no second account and no real victim. Stale-session timing on an account you control isn't a takeover.
- findings assembled from CVSS / CWE / ASVS references with no demonstrated impact
- social engineering, phishing, physical attacks, anything aimed at staff or customers
! go easy on the demo
The demo is a small, shared environment. Please don't brute-force, fuzz at volume, or run high-rate automated scans against it — you'll knock it over for everyone and trip its abuse protection, which just gets you blocked. Manual, targeted testing finds the good bugs anyway.
! white-label note
Many sites run our software for different operators. Test only against demo.comps.gg. If you think a bug hits a live operator, report it — don't reproduce it against real competitions or real customers. Those sites aren't ours to authorise you against.
## How to report
- Email [email protected] with the subject "Security Disclosure" — one issue per report. URL/endpoint, repro steps, and what an attacker gains. A short screen recording or
curl sequence beats prose.
- We triage and rate it as soon as we reasonably can, usually within a few business days. Our first reply is the triage outcome — we don't send "we got it" acknowledgements, because answering those is time not spent triaging. If you sent it, we have it. No need to chase; we'll contact you at each stage from here.
- We fix, then pay the agreed reward by PayPal and (with your OK) add you to the wall. Please hold disclosure until the fix ships.
! write it like a human
Short and real beats long and generated. We want a few lines from a person who found and understood the bug: one issue, plain English, the exact requests, and what an attacker actually gains. Please don't:
- send four pages of AI-written report — boilerplate "Summary / Description / Impact / CWE / CVSS / References" walls, ASCII flow diagrams and padded prose. We read every report; this kind goes to the back of the queue.
- let a tool find it for you — raw scanner or AI-agent output is noise until a human verifies it. We want the bug you understood and proved, not whatever a tool flagged. (High-rate automated scanning is also against the demo rules.)
- assign your own severity — don't open with "Critical" or a CVSS vector. We set severity from what you demonstrated; a "this could enable account takeover" with no shown path is just a sentence.
- theorise instead of proving — if a bug only bites a real victim, prove it with a second account you control. No PoC, no rating.
- chase for updates — "did you get it?" and "any update?" emails pull us off triage to answer them, which slows the queue for everyone, you included. Chasing a report moves it to the back of the queue, not the front. Silence means we're working through the queue; our first reply is the triage outcome.
## Safe harbour
Research in good faith and we've got your back.
If you make a sincere effort to follow this policy — in-scope targets only, don't pull more data than needed to prove the bug, don't degrade the service, don't disclose before we've fixed it — we will not pursue or support legal action against you, and we'll treat your work as authorised. If a third party comes after you over in-scope activity, we'll state on record that you acted within this policy. Unsure if something's allowed? Ask first: [email protected].
## security.txt
Lives on every site we run, so this policy is discoverable without sitting in anyone's nav. RFC 9116.
# https://comps.gg/.well-known/security.txt
Contact: mailto:[email protected]?subject=Security%20Disclosure:
Policy: https://comps.gg/security/
Acknowledgments: https://comps.gg/security/#hall-of-fame
Preferred-Languages: en
Canonical: https://comps.gg/.well-known/security.txt
## Hall of fame
Researchers who've helped keep comps.gg safe.
- Nujella Satya Siva Naga Veera Ravindra Kumar — email verification token exposed in authentication responses, and two-factor backup-code recovery blocked by a required authenticator field · June 2026
- Mohd Tahir Siddique — 2FA login authentication bypass, session invalidation after password change, internal error disclosure via duplicate-email registration, indefinite competition ticket-inventory lock via reservation refresh, unbounded input length in the profile address fields, unvalidated country values on registration and profile update, self-referral and self-exclusion evasion through Gmail address aliases, and an irreversible permanent self-exclusion settable from an unverified account · June and July 2026
- Chetan Patil — pre-account 2FA lockout via unverified email enrolment, date of birth immutability bypass, a per-user ticket limit bypassable through superseded orders, and a second unthrottled route to competition access code validation through the basket endpoint · July and August 2026
- Shubham Mali — Umami share token exposed in the public settings API · July 2026
- Harsh Gupta — internal fields exposed in authentication responses, and Turnstile not verified server-side on registration · July 2026
- gaurang maheta — authentication cookies scoped to the parent domain · July 2026
- Naveed Qadir — password-reset email rate limit bypass via the registration path · July 2026
- Soman verma — cash-to-credit conversion bonus rounding flaw allowing over-credit via batched conversions, and two-factor enrolment weaknesses (client-supplied backup codes, no password confirmation on enable) · July 2026
- Raja Das — missing input validation on the basket update endpoint, allowing a non-integer ticket quantity · July 2026
- Ravi Kumawat — password-reset token not invalidated after a password change · July 2026
- Pavan Baile — unbounded name-length input on registration and profile update, and missing password confirmation when enabling two-factor authentication · July 2026
- Jeet Pal — concurrent updates to the responsible-gambling spending limit not serialised · July 2026
- Soham D. Jadhav (Huntersoham) — the onward value of referral credit through prize-eligible entries, and an independent report of referral rewards obtainable repeatedly through Gmail address aliases · July 2026
- Gaurav Popalghat — unauthenticated stored cross-site scripting on the draw verification page enabling a forged fairness proof, referral-code validation leaking the referrer's real name, an active self-exclusion shortened to defeat responsible-gambling protection, and a payment webhook accepting unsigned requests · July 2026
- Ankit Pandey🇮🇳 — early-bird ticket pricing applied to an entire basket quantity, allowing underpayment at checkout, and an irreversible permanent self-exclusion settable from an unverified account · July 2026
- Sayada Zannat Haque — no dedicated rate limit on competition access code validation, allowing restricted competition codes to be brute-forced, and a logout endpoint reporting success while leaving refresh tokens live when none was presented · August 2026
- Karan Patil — internal prize-pool cost and financial data exposed by an unauthenticated competition endpoint · July 2026