{"id":"c9e4532a-1ed4-4c92-851d-c840eb872cd5","engagementId":"00226e37-ca3b-4aef-b28b-c24c7734aed6","data":{"brief":{"id":"8c4391ce-d9f9-4fc5-9e08-0fd93717eabb","name":"Aurory Managed Bug Bounty Engagement (Public)","tagline":"On a mission to reshape gaming","description":"\u003cp\u003eNo technology is perfect and Aurory believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"c2f2c6ac-2793-4871-a93d-2cf8c9ae10cc","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Aurory not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Cribl, you can report it to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/home\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Portal\u003c/a\u003e. However, be aware that such reports will be ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Area:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTransaction manipulation\n\n\u003cul\u003e\n\u003cli\u003eAre you able to modify a transaction to steal tokens, or reduce the cost of a purchase? \u003c/li\u003e\n\u003cli\u003eAre you able to obtain objects without purchase?\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003ePlease use header markdowns in this format:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eHeader\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-proresearcher\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eOnce you login please go to the \u003ca href=\"https://app.aurory.io/profile\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eProfile\u003c/a\u003e to update your username to include Bugcrowd. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials:\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, you can create an account from the log in section of \u003ca href=\"https://app.aurory.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.aurory.io/\u003c/a\u003e. The application allows you to login via wallet, or using Google, Discord, Facebook auth. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/home\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1fefea3f-0f88-4ddd-837f-1d4504b6dae1","name":"In Scope Targets","targets":[{"id":"e4b8364b-8331-46dd-9ccc-69591f582107","uri":"https://app.aurory.io","name":"https://app.aurory.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a25bf420-b070-41ba-91ab-9b7e01d41646","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"e4b8364b-8331-46dd-9ccc-69591f582107"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"e4b8364b-8331-46dd-9ccc-69591f582107"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e4b8364b-8331-46dd-9ccc-69591f582107"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"e4b8364b-8331-46dd-9ccc-69591f582107"}],"recentChangeFlags":null},{"id":"4a463915-89fe-4e7c-ae82-369567ad17cd","uri":"https://store.epicgames.com/p/amiko-arena-a5986d","name":"Amiko Arena","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7f017e55-0f7b-40a8-8a23-900803bbc953","sortOrder":1},"sortOrder":1,"tags":[{"id":"c2f2c6ac-2793-4871-a93d-2cf8c9ae10cc","name":"Games","targetId":"4a463915-89fe-4e7c-ae82-369567ad17cd"},{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"4a463915-89fe-4e7c-ae82-369567ad17cd"}],"recentChangeFlags":null},{"id":"cb9fb747-523d-49d9-9869-673bb164b7ee","uri":"https://store.steampowered.com/app/4245930/Amiko_Legends/","name":"Amiko Legends","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f7ad85f4-6208-4ced-89d0-e72e160b4b75","sortOrder":2},"sortOrder":2,"tags":[{"id":"c2f2c6ac-2793-4871-a93d-2cf8c9ae10cc","name":"Games","targetId":"cb9fb747-523d-49d9-9869-673bb164b7ee"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"506e1bea-d7d4-40b1-acad-b0611f94a28b","p1MaxCents":450000,"p1MinCents":350000,"p2MaxCents":250000,"p2MinCents":150000,"p3MaxCents":65000,"p3MinCents":40000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eAurory is a play-to-earn Japanese role playing game built on Solana. It is a web3 game with a marketplace and a crypto economy that rewards players with weekly distributions and more for specific events. \u003c/p\u003e\n\n\u003cp\u003ePlayers are invited to explore a rich and diverse universe where they will travel across the worlds of Antik and Tokané as they complete quests, discover lost relics, defeat enemies, and compete against other players using creatures called “Nefties\u0026quot;. Hatch eggs to obtain new Nefties, or trade with other players to build up your elite Neftie team and battle your way to the top of the leaderboard!\u003c/p\u003e\n\n\u003cp\u003eThe game was built using the Unity Game Engine, and the API is primarily NodeJS. \u003c/p\u003e\n\n\u003ch2\u003eMobile Applications (iOS and Android)\u003c/h2\u003e\n\n\u003cp\u003eBoth mobile applications are in a test version that mirror the production version to be published. Testing these thoroughly will help us release applications in top quality. \u003c/p\u003e\n\n\u003ch2\u003eAPI Docs:\u003c/h2\u003e\n\n\u003cp\u003e(\u003ca href=\"https://bugcrowd.com/engagements/aurory-mbb-og2/attachments/3e017f60-8a32-4a47-a7fa-612da46a829d\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAuroryAPIDocs.xlsx\u003c/a\u003e)\u003c/p\u003e\n\n\u003ch2\u003eGame Client \u0026amp; Server\u003c/h2\u003e\n\n\u003cp\u003eThese are sample focus areas but are not an exhaustive list for the Amiko Legends game which can be downloaded on the Epic Games launcher and the servers it interacts with.  \u003c/p\u003e\n\n\u003cp\u003eAs the server for the game is not authoritative, many in-game objects can be manipulated by the client which is known.\u003c/p\u003e\n\n\u003ch3\u003eClient-side vulnerabilities:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eExploitable memory leaks that crash the game or compromise user data.\u003c/li\u003e\n\u003cli\u003eLocal file inclusion (LFI) vulnerabilities that allow unauthorized access to game files or user data.\u003c/li\u003e\n\u003cli\u003eRemote code execution (RCE) vulnerabilities that enable attackers to execute arbitrary code on the client machine.\u003c/li\u003e\n\u003cli\u003eBuffer overflows leading to crashes or code execution.\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS) vulnerabilities that can be used to steal session cookies or inject malicious scripts into the game UI.\u003c/li\u003e\n\u003cli\u003eInsecure direct object references (IDOR) that allow unauthorized access to other player\u0026#39;s data.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eServer-side vulnerabilities:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSQL injection (SQLi) vulnerabilities that allow attackers to manipulate the game database.\u003c/li\u003e\n\u003cli\u003eServer-side RCE vulnerabilities that enable attackers to take control of the game server.\u003c/li\u003e\n\u003cli\u003eInsecure authentication and authorization flaws that allow unauthorized access to user accounts or game resources.\u003c/li\u003e\n\u003cli\u003eBroken object level authorization (BOLA) vulnerabilities that grant unauthorized access to user data.\u003c/li\u003e\n\u003cli\u003eInsecure API endpoints that can be exploited to manipulate game logic and used as unintended cheats.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eActive Smart Contract in use:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSolana Casier (aka Locker) Smart Contract: https://solscan.io/account/CAsieqooSrgVxhgWRwh21gyjq7Rmuhmo4qTW9XzXtAvW\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":3500,"max":4500},"2":{"min":1500,"max":2500},"3":{"min":400,"max":650},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f3a661ee-d9e9-4d4e-985b-dee19b57ac73","name":"Out of Scope","targets":[{"id":"3ef139ed-9199-457a-b751-7599733a663b","uri":"","name":"https://blog.aurory.io ","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d34dca08-7ad7-4057-aa01-9ea9b7f67fc4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8a6f5edd-b914-484a-ae68-a926405f4772","uri":"https://sentry.io/welcome/","name":"Sentry.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c4ee1124-e575-4734-9608-a8a32b3061cf","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"caf36cac-eb4c-4bdb-b912-9654e0e6a032","uri":"https://arbiscan.io/address/0x4e0e24b960286be46ecf92986bef548604601d77","name":"Arbitrum Casier (aka Locker) Smart Contract","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"32692735-c306-49dd-987b-9e5d2cdb4c74","sortOrder":3},"sortOrder":3,"tags":[{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"caf36cac-eb4c-4bdb-b912-9654e0e6a032"}],"recentChangeFlags":null},{"id":"244731ea-c406-4498-b3e1-97bc19bd5dd0","uri":null,"name":"wss://ws.aurorynet.dev.aurory.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"37156b73-1a2e-45f7-8ffc-1d74edc66771","sortOrder":4},"sortOrder":4,"tags":[{"id":"537a37bb-0fd5-4cb3-88b3-d08fac588565","name":"Websockets","targetId":"244731ea-c406-4498-b3e1-97bc19bd5dd0"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"3e017f60-8a32-4a47-a7fa-612da46a829d","attachmentPath":"https://bugcrowd.com/engagements/aurory-mbb-og2/attachments/3e017f60-8a32-4a47-a7fa-612da46a829d","name":"Aurory%20API%20Docs.xlsx","filename":"Aurory%20API%20Docs.xlsx","description":null,"icon":"fileOther","size":10536,"sizeLabel":"10.3 KB","uploadedAt":"3 Dec 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/aurory-mbb-og2/attachments/3e017f60-8a32-4a47-a7fa-612da46a829d"}],"engagement":{"id":"00226e37-ca3b-4aef-b28b-c24c7734aed6","code":"aurory-mbb-og2","state":"in_progress","endsAt":null,"bountyId":"0aa73162-f821-4303-b0d0-e5630d9ee914","startsAt":"2024-09-11T20:02:31Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Games","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/5ce2/c653/f20cfea9/6aba22da0a3dad9d3edf68c6a99b2dcb_Aurory_Twitter.jpg","logoBackgroundColor":"#000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-09-11T20:02:31.804Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/aurory-mbb-og2","changelogs":"/engagements/aurory-mbb-og2/changelog","submissions":null,"announcements":"/engagements/aurory-mbb-og2/announcements","hallOfFame":"/engagements/aurory-mbb-og2/hall_of_fames","crowdstream":"/engagements/aurory-mbb-og2/crowdstream"},"announcementsCount":3,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/aurory-mbb-og2/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=aurory-mbb-og2\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/aurory-mbb-og2/engagement_subscribers","engagementChangelogsUrl":"/engagements/aurory-mbb-og2/changelog","publishedAt":"2026-08-26T12:16:39.908Z","engagementChangelogUrl":"/engagements/aurory-mbb-og2/changelog/c9e4532a-1ed4-4c92-851d-c840eb872cd5","createUserFeedbacksUrl":"/engagements/aurory-mbb-og2/feedbacks","engagementCrowdstreamUrl":"/engagements/aurory-mbb-og2/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}