VDP Terms

Vulnerability Disclosure Program (VDP) Rules and Guidelines

Bina Nusantara values the efforts of security researchers in helping us maintain the security and privacy of our systems, services, and users. If you believe you have discovered a security vulnerability in a Bina Nusantara asset, we encourage you to responsibly disclose it to us through this Vulnerability Disclosure Program (VDP).

By participating in this program, you agree to comply with the following rules and guidelines.

General Rules

  • You are required to read, understand, and agree to these Rules and Guidelines, including the "In Scope" and "Out of Scope" sections available on the Bina Nusantara Vulnerability Disclosure Program portal before submitting any reports.
  • Reports must be submitted only through the designated VDP portal. Please do not contact Bina Nusantara employees directly or use other channels to report vulnerabilities.
  • Report vulnerabilities that may create a security or privacy risk to Bina Nusantara systems, services, applications, or infrastructure.
  • Any vulnerability discovered should be reported as soon as possible after discovery.
  • If you gain unintended access to sensitive information, immediately stop testing and submit a report. Do not access, modify, download, copy, store, or share any confidential information beyond what is necessary to demonstrate the existence of the vulnerability.
  • Keep all vulnerability information confidential until Bina Nusantara has completed its investigation and remediation process and has explicitly approved any public disclosure.
  • Do not discuss, disclose, or publish information about vulnerabilities without prior written permission from Bina Nusantara.
  • Do not violate any applicable laws, regulations, or third-party rights while conducting security testing.
  • Do not conduct social engineering activities, including phishing, vishing, smishing, impersonation, or any attempts to deceive Bina Nusantara employees, students, customers, or partners.
  • Do not perform physical security testing against Bina Nusantara facilities, offices, or assets.
  • Do not initiate unauthorized financial transactions.
  • Do not upload proof-of-concept artifacts containing sensitive information to public or untrusted third-party services.
  • Do not perform denial-of-service (DoS), distributed denial-of-service (DDoS), resource exhaustion, or other activities that may disrupt the availability of Bina Nusantara systems or services.
  • Do not perform destructive testing that may impact data integrity, availability, or service performance.
  • Do not spam, brute-force, credential stuff, password spray, or abuse account registration, authentication, or contact functionalities.
  • Only interact with accounts that you own or for which you have explicit authorization. Test accounts should be used whenever possible.
  • Bina Nusantara employs a risk-based method of analysis together with the CVSS calculator to assess the severity of the problem.
  • Make every effort to avoid privacy violations, service interruption, degradation of service, and destruction of data. If any such issue occurs unintentionally, notify Bina Nusantara immediately.

note: For BINUS student please use your binusian email account to submit bug, to get an additional SAT point.

In Scope

  • *.binus.ac.id 
  • *.binus.edu


Out Of Scope

  • Attacks that require physical access to a certain resource 
  • Attacks that require human interactions (social engineering) 
  • Attacks that will take down the infrastructure (DoS or DDoS) 


Responsible Disclosure Policy

We thank you for your effort, but you don't have any permission to share or publish anything related to the vulnerabilities you discovered. All you can publish is the certificate of appreciation that you received.


Report Guidelines

  • You must use the report template that has been provided by Bina Nusantara in the "Submit" section. 
  • For the security bug report, please submit your findings via email, including the attack scenario, the security impact of the bug, and the proof of concept that contains step-by-step instructions, screenshots, and the remediation. Don't forget to attach a proof-of-concept video (by link) to reproduce the vulnerability. 
  • Researchers must alert Bina Nusantara on their report if there were any privacy breaches or disruptions, such as illegal access to other users' data, service setups, or other sensitive information, that unintentionally occurred while uncovering vulnerabilities. 


FAQ

Q: What if I found a vulnerability, but I don't know how to exploit it? 

A: We expect that vulnerability reports sent to us have a valid attack scenario, and we consider it as a critical step when doing vulnerability research.  

Q: Who determines whether my report is eligible? 

A: The panel consists of the members of the Bina Nusantara Cyber Security Team. 

97de67b8d672c51c158247f398b85d31