WEBSITE SECURITY TESTING GUIDELINES
Vulnerability Reporting & Submission Instructions
Deadline: Wednesday, 20 May 2026 | 11:59 PM
1. Objective of the Task
Participants are expected to thoroughly evaluate the assigned website for security vulnerabilities and
document all issues found. The goals of this task are:
• Explore the assigned website carefully
• Check for security issues in the website
• Try to find the loopholes in the website that can be exploited by attackers
• Submit findings in a clear, structured format
• Stimulate the website with 400+ concurrent users
2. Guidelines — What To Do
Please follow these best practices while security testing:
• Report genuine vulnerabilities only
• Use clear & simple language
• Attach screenshots wherever possible
• Always mention the device and browser you used for testing
• Do NOT exploit any vulnerability beyond what is needed to confirm its existence
• Do NOT access, modify, or delete any real user data during testing
3. How to Report a Security Bug
Each vulnerability must be reported using the standard format below
SECURITY BUG REPORT TEMPLATE
Title — Short description of the vulnerability / issue
Application used --- Name of application used
Result — What actually happened
Screenshot — Attach screenshot or proof-of-concept if possible
Device / Browser Example: Chrome on Android, Firefox on Windows
4. Method of Submission
Follow these steps to submit your findings:
1. Create a single document listing all bugs with proper numbering
2. Add screenshots files for each bug to the same Google Drive folder
3. Upload both the document and all supporting files to one shared Google Drive folder
4. Change the folder access to "Anyone with the link can view"
5. Share the Drive folder link .
NOTE: Ensure the Google Drive folder access is set to "Anyone with the link can view" before sharing
the link, otherwise reviewers will not be able to access your submission.
5. Deadline
Submit on or before: Thursday, 21 May 2026 at 12 noon
Late submissions may not be accepted. Ensure your Drive folder is shared and accessible before the
deadline.