is there any bug bountys?

Place to post guides, observations, things related to modding that are not mods themselves.
ilikehackinggames
Inserter
Inserter
Posts: 20
Joined: Thu Apr 24, 2025 11:51 pm
Contact:

is there any bug bountys?

Post by ilikehackinggames »

im working on fuzzing the lua parser with a lexser and was wondering if i find any security vunerabilitys where i should report them. i already found a segfault but i dont think its useful. will report it soon.
eugenekay
Filter Inserter
Filter Inserter
Posts: 503
Joined: Tue May 15, 2018 2:14 am
Contact:

Re: is there any bug bountys?

Post by eugenekay »

Edit: New guidance from Staff is in the next Reply.

I have never seen a Bug Bounty discussed; Wube Software is a small team. Most of us Players are here for the Fun of it. :-)

There is not an official separate Security Contact - it says “Our main communication point is our official forum”, so you’re already in the right place. Receiving a reply from support@factorio.com for Security related disclosures concerning the website Infrastructure previously has not been responsive for me; But I have tried. Nothing serious enough to warrant a CVE or widely applicable, but there is always a hole somewhere…

I personally have fuzzed the Network code using some Automated tools, and did not find anything that would result in remote code execution (except for that inside the Lua Sandbox, which is intentional as part of the Game). I did not look for any Sandbox exploits myself; but I think that there had been an issue with that before the 1.0 release…. Good Luck in your hunting!
Last edited by eugenekay on Sun Apr 27, 2025 4:14 pm, edited 2 times in total.
Bilka
Factorio Staff
Factorio Staff
Posts: 3385
Joined: Sat Aug 13, 2016 9:20 am
Contact:

Re: is there any bug bountys?

Post by Bilka »

Please report security vulnerabilities privately at factorio@factorio.com
I'm an admin over at https://wiki.factorio.com. Feel free to contact me if there's anything wrong (or right) with it.
ilikehackinggames
Inserter
Inserter
Posts: 20
Joined: Thu Apr 24, 2025 11:51 pm
Contact:

Re: is there any bug bountys?

Post by ilikehackinggames »

eugenekay wrote: Sun Apr 27, 2025 12:02 am Edit: New guidance from Staff is in the next Reply.

I have never seen a Bug Bounty discussed; Wube Software is a small team. Most of us Players are here for the Fun of it. :-)
yea thats fair. though if i did find a rce (unlikely) i would hope they would at least be willing to give me a free copy of SA or something lol
Post Reply

Return to “Modding discussion”