Zaplat GamingZAPLAT GAMINGCOMMUNITY PLATFORM
ZAPLAT GAMING ↗
ZAPLAT GAMING • SECURITY

الأمان والإبلاغ المسؤول عن الثغرات

نأخذ أمن حسابات وبيانات مجتمع Zaplat Gaming بجدية. توضح هذه الصفحة الطريقة الصحيحة للإبلاغ عن ثغرة محتملة ومبادئ الاختبار المسؤول.

22 Sep 2026zaplatgaming.com

1. الإبلاغ المسؤول

إذا اكتشفت مشكلة أمنية محتملة، استخدم وأرسل التفاصيل مباشرة إلى الإدارة. اذكر الصفحة أو الميزة المتأثرة، خطوات إعادة المشكلة، الأثر المتوقع، وأي لقطات أو معلومات فنية تساعد على التحقق. لا ترسل كلمات مرور أو رموز جلسات حقيقية تخص أشخاصًا آخرين.

2. قواعد الاختبار بحسن نية

استخدم حساباتك وبياناتك فقط. لا تصل إلى بيانات الآخرين، ولا تغيّر أو تحذف بيانات ليست لك، ولا تنفذ هجمات حجب خدمة أو إغراق أو هندسة اجتماعية، ولا تستخدم ثغرة لمواصلة الوصول بعد إثباتها بالحد الأدنى اللازم. امنحنا وقتًا معقولًا للتحقق والمعالجة قبل نشر تفاصيل قابلة للاستغلال.

3. ما الذي نريد معرفته

نرحب بالتقارير عن تجاوز تسجيل الدخول أو الصلاحيات، كشف بيانات خاصة، XSS أو حقن أو CSRF، وصول غير مصرح به إلى API أو ملفات، أخطاء رفع الملفات، أو أي سلوك يسمح بتجاوز حدود الأمان. الأعطال العامة والمشاكل الوظيفية غير الأمنية يمكن إرسالها عبر قنوات الدعم المعتادة.

4. طبقات الحماية

نستخدم ضوابط من جهة الخادم للصلاحيات، تحققًا من أصل الطلبات الحساسة، حدودًا لمعدلات الاستخدام، تحققًا من الملفات، رؤوس أمان للمتصفح، سجلات تشغيلية، وضوابط على الأسرار والنشر. تتغير الضوابط مع تطور المنصة، ولا يعني وصفها ضمانًا بعدم وجود أي ثغرة.

5. النطاق والخدمات الخارجية

قد تعتمد بعض الميزات على خدمات خارجية مثل Cloudflare وGoogle وYouTube وSteam ومنصات البث. الثغرات الموجودة حصريًا في خدمة خارجية يجب الإبلاغ عنها إلى مالك تلك الخدمة، مع إبلاغنا أيضًا إذا كان تكامل Zaplat Gaming يتأثر بها.

6. المكافآت والتواصل

لا يوجد حاليًا برنامج مكافآت مالية معلن لاكتشاف الثغرات. سنراجع البلاغات الجادة بحسن نية ونتعامل معها حسب الخطورة والأثر المتاحين.

ZAPLAT GAMING • SECURITY

Security and responsible disclosure

We take the security of Zaplat Gaming accounts and community data seriously. This page explains how to report a potential vulnerability and how to test responsibly.

22 Sep 2026zaplatgaming.com

1. Responsible disclosure

If you discover a potential security issue, use to send the details directly to the administration. Include the affected page or feature, reproducible steps, expected impact, and any screenshots or technical details that help verification. Do not send passwords or live session tokens belonging to other people.

2. Good-faith testing

Use only accounts and data you control. Do not access, modify or delete other people’s data, perform denial-of-service or flooding, use social engineering, or continue exploitation beyond the minimum needed to demonstrate an issue. Give us reasonable time to verify and fix an issue before publishing exploit-ready details.

3. Useful reports

We welcome reports about authentication or authorization bypass, private-data exposure, XSS, injection, CSRF, unauthorized API or file access, unsafe uploads, or behavior that bypasses security boundaries. General bugs that are not security issues can be sent through normal support channels.

4. Security layers

We use server-side authorization, origin checks for sensitive requests, rate limits, file validation, browser security headers, operational logging, and controls around secrets and deployment. These controls evolve with the platform and do not constitute a guarantee that vulnerabilities can never exist.

5. Scope and third parties

Some features depend on third-party services such as Cloudflare, Google, YouTube, Steam and streaming platforms. Vulnerabilities that exist exclusively in an external service should be reported to that provider; please also tell us if the Zaplat Gaming integration is affected.

6. Rewards and contact

There is currently no announced monetary bug-bounty program. Serious good-faith reports will be reviewed and handled according to the available evidence, impact and severity.

ZAPLAT GAMING • SEGURIDAD

Seguridad y divulgación responsable

Nos tomamos en serio la seguridad de las cuentas y los datos de la comunidad de Zaplat Gaming. Esta página explica cómo informar de una posible vulnerabilidad y cómo realizar pruebas de forma responsable.

22 sep 2026zaplatgaming.com

1. Divulgación responsable

Si descubres un posible problema de seguridad, utiliza para enviar los detalles directamente a la administración. Incluye la página o función afectada, pasos reproducibles, impacto esperado y cualquier captura o detalle técnico que ayude a verificarlo. No envíes contraseñas ni tokens de sesión activos pertenecientes a otras personas.

2. Pruebas de buena fe

Utiliza únicamente cuentas y datos que controles. No accedas, modifiques ni elimines datos de otras personas, no realices ataques de denegación de servicio o inundación, no utilices ingeniería social y no continúes explotando un problema más allá de lo mínimo necesario para demostrarlo. Danos un tiempo razonable para verificar y corregir el problema antes de publicar detalles listos para su explotación.

3. Informes útiles

Agradecemos informes sobre bypass de autenticación o autorización, exposición de datos privados, XSS, inyección, CSRF, acceso no autorizado a API o archivos, cargas inseguras o comportamientos que eludan los límites de seguridad. Los errores generales que no sean problemas de seguridad pueden enviarse por los canales normales de soporte.

4. Capas de seguridad

Utilizamos autorización del lado del servidor, comprobaciones de origen para solicitudes sensibles, límites de frecuencia, validación de archivos, cabeceras de seguridad del navegador, registros operativos y controles sobre secretos y despliegues. Estas medidas evolucionan con la plataforma y no constituyen una garantía de que nunca puedan existir vulnerabilidades.

5. Alcance y terceros

Algunas funciones dependen de servicios de terceros como Cloudflare, Google, YouTube, Steam y plataformas de streaming. Las vulnerabilidades que existan exclusivamente en un servicio externo deben comunicarse a ese proveedor; infórmanos también si la integración con Zaplat Gaming se ve afectada.

6. Recompensas y contacto

Actualmente no existe un programa público anunciado de recompensas económicas por vulnerabilidades. Los informes serios y de buena fe se revisarán y gestionarán según las pruebas disponibles, el impacto y la gravedad.

ZAPLAT GAMING • SECURITY

Güvenlik ve sorumlu bildirim

Zaplat Gaming hesaplarının ve topluluk verilerinin güvenliğini ciddiye alıyoruz. Bu sayfa olası bir güvenlik açığının nasıl bildirileceğini ve sorumlu test ilkelerini açıklar.

22 Sep 2026zaplatgaming.com

1. Sorumlu bildirim

Olası bir güvenlik sorunu bulursanız ayrıntıları doğrudan yönetime göndermek için seçeneğini kullanın. Etkilenen sayfa veya özellik, tekrar adımları, olası etki ve doğrulamaya yardımcı teknik ayrıntıları ekleyin. Başkalarına ait parola veya canlı oturum belirteçlerini göndermeyin.

2. İyi niyetli test

Yalnızca kontrol ettiğiniz hesap ve verileri kullanın. Başkalarının verilerine erişmeyin, değiştirmeyin veya silmeyin; hizmet engelleme, flooding ya da sosyal mühendislik yapmayın; sorunu göstermek için gereken asgari seviyenin ötesinde istismara devam etmeyin. İstismar ayrıntılarını yayımlamadan önce doğrulama ve düzeltme için makul süre tanıyın.

3. Faydalı raporlar

Kimlik doğrulama veya yetki atlama, özel veri ifşası, XSS, injection, CSRF, yetkisiz API/dosya erişimi, güvensiz yüklemeler ve güvenlik sınırlarını aşan davranışlar hakkında raporları kabul ediyoruz.

4. Güvenlik katmanları

Sunucu tarafı yetkilendirme, hassas isteklerde origin kontrolleri, rate limit, dosya doğrulama, tarayıcı güvenlik başlıkları, operasyon kayıtları ve secret/deploy kontrolleri kullanıyoruz. Bu katmanlar zamanla gelişir ve hiçbir zaman mutlak güvenlik garantisi anlamına gelmez.

5. Kapsam ve üçüncü taraflar

Bazı özellikler Cloudflare, Google, YouTube, Steam ve yayın platformları gibi üçüncü taraf hizmetlere bağlıdır. Yalnızca harici hizmette bulunan açıklar ilgili sağlayıcıya bildirilmelidir; Zaplat Gaming entegrasyonu etkileniyorsa bize de bildirin.

6. Ödül ve iletişim

Şu anda ilan edilmiş ücretli bir bug-bounty programımız yoktur. Ciddi ve iyi niyetli raporlar mevcut kanıt, etki ve önem derecesine göre incelenir.

ZAPLAT GAMING • SECURITY

Sécurité et divulgation responsable

Nous prenons au sérieux la sécurité des comptes et des données de la communauté Zaplat Gaming. Cette page explique comment signaler une vulnérabilité potentielle et tester de manière responsable.

22 Sep 2026zaplatgaming.com

1. Signalement responsable

Si vous découvrez un problème de sécurité potentiel, utilisez pour envoyer les détails directement à l’administration. Indiquez la page ou fonction concernée, les étapes de reproduction, l’impact attendu et les détails techniques utiles. N’envoyez pas de mots de passe ou jetons de session actifs appartenant à d’autres personnes.

2. Tests de bonne foi

Utilisez uniquement vos propres comptes et données. N’accédez pas aux données d’autrui, ne les modifiez ni ne les supprimez, n’effectuez pas de déni de service, de flooding ou d’ingénierie sociale, et limitez toute démonstration au strict minimum. Laissez-nous un délai raisonnable pour vérifier et corriger avant toute publication exploitable.

3. Rapports utiles

Nous acceptons les signalements concernant le contournement de l’authentification ou des autorisations, l’exposition de données privées, XSS, injection, CSRF, accès API/fichiers non autorisé, téléversements dangereux ou contournement de limites de sécurité.

4. Couches de sécurité

Nous utilisons notamment des autorisations côté serveur, des contrôles d’origine, des limites de débit, la validation des fichiers, des en-têtes de sécurité navigateur, des journaux opérationnels et des contrôles sur les secrets et le déploiement. Ces mesures évoluent et ne garantissent pas l’absence absolue de vulnérabilités.

5. Portée et tiers

Certaines fonctions dépendent de services tiers comme Cloudflare, Google, YouTube, Steam et des plateformes de streaming. Une faille exclusivement présente chez un tiers doit être signalée à ce fournisseur; informez-nous aussi si l’intégration Zaplat Gaming est affectée.

6. Récompenses et contact

Aucun programme public de récompense financière n’est actuellement annoncé. Les rapports sérieux et de bonne foi seront examinés selon les preuves, l’impact et la gravité disponibles.

ZAPLAT GAMING • SECURITY

Sicherheit und verantwortungsvolle Meldung

Wir nehmen die Sicherheit von Zaplat-Gaming-Konten und Community-Daten ernst. Diese Seite erklärt, wie mögliche Schwachstellen gemeldet und verantwortungsvoll getestet werden können.

22 Sep 2026zaplatgaming.com

1. Verantwortungsvolle Meldung

Wenn du ein mögliches Sicherheitsproblem findest, nutze , um die Details direkt an die Verwaltung zu senden. Nenne betroffene Seite/Funktion, reproduzierbare Schritte, erwartete Auswirkungen und hilfreiche technische Details. Sende keine Passwörter oder aktiven Sitzungstoken anderer Personen.

2. Tests in gutem Glauben

Nutze nur Konten und Daten, die du kontrollierst. Greife nicht auf fremde Daten zu, ändere oder lösche sie nicht, führe keine DoS-/Flooding-Angriffe oder Social Engineering durch und gehe nicht über das Mindestmaß hinaus, das zur Demonstration nötig ist. Gib uns angemessene Zeit zur Prüfung und Behebung, bevor ausnutzbare Details veröffentlicht werden.

3. Hilfreiche Meldungen

Willkommen sind Berichte über Umgehung von Authentifizierung oder Berechtigungen, Offenlegung privater Daten, XSS, Injection, CSRF, unberechtigten API-/Dateizugriff, unsichere Uploads oder andere Umgehungen von Sicherheitsgrenzen.

4. Sicherheitsebenen

Wir nutzen serverseitige Autorisierung, Origin-Prüfungen für sensible Anfragen, Rate Limits, Dateiprüfung, Browser-Sicherheitsheader, Betriebsprotokolle sowie Kontrollen für Secrets und Deployments. Diese Maßnahmen entwickeln sich weiter und sind keine Garantie für absolute Fehlerfreiheit.

5. Umfang und Dritte

Einige Funktionen hängen von Drittanbietern wie Cloudflare, Google, YouTube, Steam und Streaming-Plattformen ab. Schwachstellen, die ausschließlich bei einem Drittanbieter liegen, sollten dort gemeldet werden; informiere uns zusätzlich, wenn unsere Integration betroffen ist.

6. Belohnungen und Kontakt

Derzeit gibt es kein öffentlich angekündigtes finanzielles Bug-Bounty-Programm. Ernsthafte Meldungen in gutem Glauben werden nach Belegen, Auswirkungen und Schweregrad geprüft.

ZAPLAT GAMING • SECURITY

Sicurezza e segnalazione responsabile

Prendiamo sul serio la sicurezza degli account e dei dati della community Zaplat Gaming. Questa pagina spiega come segnalare una possibile vulnerabilità e come effettuare test responsabili.

22 Sep 2026zaplatgaming.com

1. Segnalazione responsabile

Se scopri un possibile problema di sicurezza, usa per inviare i dettagli direttamente all’amministrazione. Includi pagina o funzione interessata, passaggi riproducibili, impatto previsto e dettagli tecnici utili. Non inviare password o token di sessione attivi appartenenti ad altre persone.

2. Test in buona fede

Usa solo account e dati sotto il tuo controllo. Non accedere, modificare o cancellare dati altrui, non eseguire denial-of-service, flooding o social engineering e limita qualsiasi dimostrazione al minimo necessario. Concedici un tempo ragionevole per verificare e correggere prima di pubblicare dettagli sfruttabili.

3. Segnalazioni utili

Accogliamo segnalazioni su bypass di autenticazione o autorizzazione, esposizione di dati privati, XSS, injection, CSRF, accesso non autorizzato ad API/file, upload non sicuri o altri bypass dei confini di sicurezza.

4. Livelli di sicurezza

Utilizziamo autorizzazione lato server, controlli di origine per richieste sensibili, rate limiting, validazione dei file, header di sicurezza del browser, log operativi e controlli su secret e deployment. Queste misure evolvono e non costituiscono una garanzia assoluta contro ogni vulnerabilità.

5. Ambito e terze parti

Alcune funzioni dipendono da servizi terzi come Cloudflare, Google, YouTube, Steam e piattaforme di streaming. Le vulnerabilità presenti esclusivamente in un servizio esterno vanno segnalate al relativo fornitore; informaci anche se l’integrazione Zaplat Gaming è coinvolta.

6. Ricompense e contatto

Al momento non è annunciato alcun programma pubblico di bug bounty a pagamento. Le segnalazioni serie e in buona fede saranno esaminate in base alle prove, all’impatto e alla gravità disponibili.

© 2026 Zaplat Gaming. جميع الحقوق محفوظة.All rights reserved.Tüm hakları saklıdır.Tous droits réservés.Alle Rechte vorbehalten.Tutti i diritti riservati.Todos los derechos reservados.
الخصوصيةPrivacyGizlilikConfidentialitéDatenschutzPrivacyPrivacidadالشروطTermsŞartlarConditionsBedingungenTerminiTérminosالملكية الفكريةIntellectual PropertyFikri MülkiyetPropriété intellectuelleGeistiges EigentumProprietà intellettualePropiedad intelectual