{"id":"dd3672f0-00b7-48ec-939d-8fa9532c35d6","engagementId":"8f8641dd-d889-4c75-8117-97035a7854a7","data":{"brief":{"id":"57cfe595-1497-43fe-8fe3-49898e78b7dc","name":"Bitdefender Box v2","tagline":"Internet security solution that incorporates hardware, cloud and software designed to protect your smart home and your family.","description":"\u003cp\u003eBitdefender BOX protects all devices connected to the Internet, not just a laptop or desktop computer. BOX secures smartphones, smart TVs, and all your other home appliances, like Wi-Fi thermostats, gaming consoles, and even your baby monitor). BOX can be controlled from the central website or the easy-to-use mobile app. \u003c/p\u003e\n\n\u003ch2\u003eBitdefender Box2 Testing Device\u003c/h2\u003e\n\n\u003cp\u003eResearchers must supply their own device for testing. If you don't already own a Box2, you can acquire a device in 2 ways: \u003cbr\u003e\n1) Purchase a device through the \u003ca href=\"https://www.bitdefender.com/box/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBitdefender website\u003c/a\u003e.\u003cbr\u003e\n2) Qualify as an \"Expert Researcher\" (survey link below). \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRewards \u0026amp; Priorities\u003c/h2\u003e\n\n\u003cp\u003eThe scope of this bounty program is to find vulnerabilities that can be exploited as a guest, or remotely. (e.g. a friend coming at your place, connecting to your WIFI network and hack your box device OR exploiting other customer devices remotely).\u003c/p\u003e\n\n\u003cp\u003eIt's important to note that the Bitdefender Box communicates through a cloud app - however, this program is provided exclusively for the reporting of security issues pertaining to any communication directly to/from the Box itself. If you're able to identify any vulnerabilities in the cloud app, they should be reported here: \u003ca href=\"https://bugcrowd.com/bitdefender\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.com/bitdefender\u003c/a\u003e. The Bitdefender Security team will determine the nature and impact of the vulnerabilities at their sole discretion. The following vulnerabilities are in-scope for the program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e1.a) \u003cstrong\u003eRemote Code Execution\u003c/strong\u003e - Ability to get remote code execution against the BOX without proper authorization (not on the same LAN) - achieving this objective will be rewarded in the range of 5000$\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e1.b) Ability to access/control the BOX remotely without proper authorization (not on the same LAN) - reward varies depending on impact\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e2.a) \u003cstrong\u003eRemote Code Execution\u003c/strong\u003e - Ability to get remote code execution against the BOX without proper authorization (ON the same LAN) - achieving this objective will be rewarded in the range of 2500$\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e2.b) Ability to access/control the BOX without proper authorization (ON the same LAN) - reward varies depending on impact\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e3.a) \u003cstrong\u003eDOS\u003c/strong\u003e - crash our product remotely (not on the same LAN) - 2500$\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e3.b) \u003cstrong\u003eDOS\u003c/strong\u003e - crash our product (ON the same LAN) - 1000$\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cem\u003eAttacking your own device from a BOX Administrator standpoint is not eligible for reward\u003c/em\u003e\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eVulnerabilities submitted which are not included in the above list may not be rewarded. This is decided at the sole discretion of the Bitdefender team. See \u003ccode\u003eScope - Additional Details\u003c/code\u003e for more information on scoping. Furthermore, ONLY vulnerabilities on BOX products are out-of-scope. Vulnerabilities found on Bitdefender mobile apps \u0026amp; \u003ccode\u003ecentral.bitdefender.com\u003c/code\u003e are out-of-scope.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccount Setup - Mobile App\u003c/h2\u003e\n\n\u003cp\u003eAll instructions for the product are in the BOX package (default passwords, how to configure, etc). To configure/setup BOX v2, install the \"Bitdefender Central\" mobile application. Create an account or log in using an existing account. User accounts are shared by the mobile \u0026amp; web apps. Please note that the mobile app is not in scope for this program. However, if you believe you've found a way to be able to control someone else's device via the mobile app, you're encouraged to submit it - and we'll review whether it's in scope or rewardable.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003eAndroid:\u003c/em\u003e \u003ca href=\"https://play.google.com/store/apps/details?id=com.bitdefender.centralmgmt\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://play.google.com/store/apps/details?id=com.bitdefender.centralmgmt\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003eiOS:\u003c/em\u003e \u003ca href=\"https://itunes.apple.com/ro/app/bitdefender-central/id969933082?mt=8\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://itunes.apple.com/ro/app/bitdefender-central/id969933082?mt=8\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eAccount Setup - Web App\u003c/h2\u003e\n\n\u003cp\u003eThe BOX is managed via the Bitdefender Central App \u003ca href=\"https://central.bitdefender.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://central.bitdefender.com\u003c/a\u003e. Login using the same account registered via the mobile application. User accounts are shared by the mobile \u0026amp; web apps. Please note that any vulnerabilities found in the webapp should be reported here: \u003ca href=\"https://bugcrowd.com/bitdefender\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.com/bitdefender\u003c/a\u003e - and not to this program.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eAny domain/property of Bitdefender or associated business entities not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/p\u003e\n\n\u003ch2\u003eScope - Additional Details\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eVulnerabilities that can be exploited as a guest or remotely. (e.g. a friend coming to your home, connecting to your WIFI network, and hacking your BOX device OR exploiting other customer devices remotely). \u003cem\u003ePlease DO NOT attack any devices, accounts, or networks that are not yours.\u003c/em\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThe Bitdefender BOX communicates through a CLOUD APP. While the cloud app is not in scope for this program, if you're able to identify any vulnerabilities in this web application, please submit here: \u003ca href=\"https://bugcrowd.com/bitdefender\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.com/bitdefender\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eVulnerabilities discovered in \"Bitdefender Central\" -- mobile applications (iOS \u0026amp; Android) are NOT IN SCOPE!\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eONLY BOX Products and Services are in-scope for this program (other Bitdefender products \u0026amp; services are available via BOX, but are out-of-scope for this program). \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you find a vulnerability on a non-BOX product or service, please submit it via the \u003ca href=\"https://bugcrowd.com/bitdefender\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBitdefender Public Program\u003c/a\u003e. \u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eA closer look at how it works:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eSAFE BROWSING - Bitdefender BOX blocks all unsafe or malicious URLs to protect against phishing \u0026amp; online fraud.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eVULNERABILITY ASSESSMENT - Bitdefender BOX continuously scans, identifies and highlights network security flaws.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eEXPLOIT PREVENTION - Identify and block attempts to exploit vulnerabilities in your devices and network.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eADVANCED PARENTAL CONTROLS - Efficient and intuitive tools to manage daily Internet time, set content filters by age categories or pause the Internet altogether for precious family time. \u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eDEVICE MANAGEMENT - Whenever a new device connects to your network, Bitdefender BOX promptly detects it and sends an instant notification to your Bitdefender Central app so you can take action and control what that device is allowed to do.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eLOCAL DEVICE SECURITY - Bitdefender BOX includes Total Security, our award winning cybersecurity suite to protect all your laptops, desktops, smartphones and tablets, across Windows, macOS, iOS and Android. These are not in the scope of this program. You can submit any issues related to Bitdefender Total Security on the \u003ca href=\"https://bugcrowd.com/bitdefender\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Bitdefender Public Program\u003c/a\u003e.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eANOMALY DETECTION - Bitdefender BOX understands how devices should behave under normal circumstances and is able to accurately identify, block and alert you upon any malicious activity.\nThe learning period is about 2 weeks in which the BOX generates a model for the protected device. The model won't be created for devices which generate a lot of noise ( e.g. laptops). It will be generated for devices which have simple patterns - e.g. IOT devices\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eBRUTE-FORCE PROTECTION - The brute force protection technology will prevent hackers from taking control over your devices.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003cli\u003e\u003col\u003e\n\u003cli\u003eSENSITIVE DATA PROTECTION - No sensitive information sent without encryption. This feature will identify whenever credit card information, authentication information or location data is sent over a non-encrypted connection and block the attempt.\u003c/li\u003e\n\u003c/ol\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy; \u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls; \u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy;\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our official channels before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e15dcca0-3131-47af-a9ec-3c47b2575197","name":"In scope","targets":[{"id":"b77d5a54-6af7-470b-a94d-c30f4497d679","uri":null,"name":"Bitdefender BOX v2","category":"iot","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5b1318c6-68e5-49e3-b044-ca69fb7e3466","sortOrder":0},"sortOrder":0,"tags":[{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"b77d5a54-6af7-470b-a94d-c30f4497d679"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"254d5f98-8d7d-4e90-bae1-085e92cefc66","p1MaxCents":500000,"p1MinCents":250000,"p2MaxCents":250000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2500,"max":5000},"2":{"min":1000,"max":2500},"3":{"min":500,"max":1000},"4":{"min":200,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a7c114e4-3d39-4892-8b7a-d17cd443a5b0","name":"Out of scope","targets":[{"id":"a3b8cb6e-b3a3-488b-b59f-d3d4fb0c65f9","uri":null,"name":"Bitdefender Central (iOS App)","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fd23c795-65d8-436f-abae-5f8fb83ee887","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"a3b8cb6e-b3a3-488b-b59f-d3d4fb0c65f9"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"a3b8cb6e-b3a3-488b-b59f-d3d4fb0c65f9"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"a3b8cb6e-b3a3-488b-b59f-d3d4fb0c65f9"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"a3b8cb6e-b3a3-488b-b59f-d3d4fb0c65f9"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"a3b8cb6e-b3a3-488b-b59f-d3d4fb0c65f9"}],"recentChangeFlags":null},{"id":"d64a2d25-4362-48e1-b9b1-602a1a3d7978","uri":null,"name":"Bitdefender Central (Android App)","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"76a67809-a496-43e7-b788-d3cba5246bfe","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"d64a2d25-4362-48e1-b9b1-602a1a3d7978"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"d64a2d25-4362-48e1-b9b1-602a1a3d7978"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"d64a2d25-4362-48e1-b9b1-602a1a3d7978"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"d64a2d25-4362-48e1-b9b1-602a1a3d7978"}],"recentChangeFlags":null},{"id":"bdea11bf-21b7-44e2-a617-95704f2dd182","uri":null,"name":"central.bitdefender.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"59a5dcb9-36f6-42f1-aeaf-f7062be102db","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bdea11bf-21b7-44e2-a617-95704f2dd182"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"8f8641dd-d889-4c75-8117-97035a7854a7","code":"bitdefenderbox2","state":"in_progress","endsAt":null,"bountyId":"01dcafe8-4b1f-494d-a19d-f6a511f347a0","startsAt":"2018-02-22T20:30:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/749c/face/61362a72/42c35f74a1b7ede92978e5caed56d3e7_Untitled.jpg","logoBackgroundColor":"#D80916","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-02-22T20:30:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/bitdefenderbox2","changelogs":"/engagements/bitdefenderbox2/changelog","submissions":null,"announcements":"/engagements/bitdefenderbox2/announcements","hallOfFame":"/engagements/bitdefenderbox2/hall_of_fames","crowdstream":"/engagements/bitdefenderbox2/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/bitdefenderbox2/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=bitdefenderbox2\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/bitdefenderbox2/engagement_subscribers","engagementChangelogsUrl":"/engagements/bitdefenderbox2/changelog","publishedAt":"2020-02-13T00:32:33.727Z","engagementChangelogUrl":"/engagements/bitdefenderbox2/changelog/dd3672f0-00b7-48ec-939d-8fa9532c35d6","createUserFeedbacksUrl":"/engagements/bitdefenderbox2/feedbacks","engagementCrowdstreamUrl":"/engagements/bitdefenderbox2/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}