Illinois Proxies logo
Security

Responsible disclosure & bug bounty policy

If Illinois Proxies has a vulnerability you have found, we would like to hear about it. Below we lay out the scope, what we pay for and what we do not, and how to report, so neither side gets surprised.

Scope

In scope

  • This website, illinoisproxies.com
  • The customer dashboard you log in to, along with its API
  • How the dashboard handles rotation links, API keys and proxy credentials

Out of scope

  • Modem hosts, proxy gateways and the mobile carrier networks behind them
  • Outside services such as payment processors, Telegram, Cloudflare and email providers
  • Marketing assets served from legacy CDN paths
  • Customer accounts or data belonging to anyone but you

What we pay

We reward demonstrated impact on our systems or on our customers. Amounts are in USD.

Critical
$100 – $250
  • Remote code execution on our servers
  • SQL injection able to read or write customer data
  • Bypassing authentication to enter any account without its credentials
  • Manipulating payments or balances to obtain proxies, credit or refunds without paying
  • Exposure, at scale, of other customers' proxy credentials or personal data
High
$50 – $100
  • Viewing or modifying another customer's proxies, orders or account details (IDOR)
  • Stored XSS that executes in an admin's or another customer's session
  • Escalating privileges from a customer account into admin functions
  • Server-side request forgery reaching internal services
  • Stealing another account's API key, rotation link or session
Medium
$20 – $50
  • Cross-site request forgery against any action that changes account state
  • Reflected cross-site scripting that only fires when the victim clicks a link
  • Bypassing a rate limit in a way that leads to a demonstrated account takeover
  • Business-logic or pricing errors that have a demonstrated financial impact
Low / Informational
$0

We acknowledge these and fix where warranted; no payment. You can check the full list below before writing your report.

What we do not pay for

At most, we accept these as Low or Informational. We read them and fix what deserves fixing, though no bounty is issued, even if the report is labeled Critical or High.

  • Session tokens that remain usable after logout, a password change or a password reset, until they expire
  • Security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) that are missing or “weak”, with no working exploit
  • Clickjacking on pages without any sensitive action
  • Attributes on cookies other than session cookies
  • Enumeration of emails or usernames, whether through timing, error messages or otherwise
  • Observations about login, forgot-password or rate limits that do not demonstrate an account takeover
  • Opinions on password policy, such as length, complexity, common-password lists or the lack of forced rotation
  • No two-factor authentication, or 2FA offered only as an option
  • Self-XSS, as well as XSS the attacker can trigger only in their own session
  • CSRF on logout, login, language or any other non-sensitive form
  • Open redirects that leak no token or credential
  • Disclosure of software versions, server banners, stack traces or paths that contains no sensitive data
  • SPF, DKIM or DMARC configuration reports
  • Automated scanner output with no proof of concept
  • Brute force, resource exhaustion, denial of service or any test that generates load
  • Phishing or social engineering aimed at our staff or customers, and physical attacks
  • Problems in third-party services we rely on, such as payment processors, Telegram, Cloudflare and email providers
  • Old library versions with no working exploit against our deployment
  • Attacks that depend on a rooted phone, a compromised device or a man-in-the-middle position
  • Theoretical risks, best-practice recommendations and duplicates of issues already known

Rules of engagement

  1. First valid report wins. We do not pay for duplicates or for reports of issues already known to us. Each root cause is paid once, no matter how many endpoints it touches.
  2. Prove it, then stop. Access only your own accounts and data. Should a test expose someone else's data, stop at the first proof and report it, without pivoting, downloading or persisting.
  3. Do not degrade the service. Load testing, high-volume automated fuzzing and tests against proxy gateways, modem hosts or carrier networks are not allowed. Those are out of scope entirely.
  4. Give us time. Please hold off publishing until the issue is fixed and 30 days have passed. We will let you know once a fix is live.
  5. Severity is ours to set. Impact is rated against our own systems, with the Bugcrowd Vulnerability Rating Taxonomy as our reference. Within the ranges above, we set payment amounts at our discretion and pay them by PayPal or USDT.
Safe harbour. Research that follows these rules is authorised. For good-faith testing within scope we will not take legal action against you, and we ask the same good faith from you in return: no extortion, no threats of disclosure, no “pay first, details later”.

How to report

Email [email protected] with the subject Security report. Your report should include the affected URL, the exact steps to reproduce, the account you used and a proof of concept. Expect an acknowledgment within 5 business days and a severity decision within 10 business days.

Machine-readable contact details are at /.well-known/security.txt.

Send a report

Policy last updated 2026-10-10.