{"id":"f1b3e165-6a70-418d-9df3-180f38f07907","engagementId":"21ec57ac-a854-4a75-bcb2-473dd4cd2b68","data":{"brief":{"id":"e4d7c7e6-165f-417e-8359-13b7b853e367","name":"Comcast Xfinity Bug Bounty","tagline":"Welcome to the Xfinity Bug Bounty program!","description":"\u003cp\u003eWelcome to the Xfinity Bug Bounty program! This program will be trialing our first comprehensive paid rewards program for the products that shape the Xfinity consumer experience. We're offering higher-paying rewards in more categories to an exclusive group of researchers. We are excited for you to help us identify vulnerabilities in our applications and grow our bug bounty program. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority and reward will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eNote the following amendments for this program:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eVRT Name\u003c/th\u003e\n\u003cth\u003eAdjusted Priority\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eHigh Impact Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP2 -\u0026gt; P3\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eBasic Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP3 -\u0026gt; P4\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eComcast provides Xfinity Internet, TV, wireless, home automation, and more to tens of millions of residential customers. With so many devices and services in homes, it has never been more important to ensure the security of those products while striving to deliver an experience that is simple, elegant, and powerful. With this in mind, we remain committed to working with security researchers and alongside the security community, and will maintain trust, respect, and transparency that aligns with our commitment to security and privacy.\u003c/p\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eWe do not offer accounts or credentials for testing purposes.\u003c/p\u003e\n\n\u003ch3\u003eIP address\u003c/h3\u003e\n\n\u003cp\u003ePlease provide your IP address in the report while submitting the P1/P2 finding. \u003c/p\u003e\n\n\u003ch3\u003eCustom User-Agent Header\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior:\u003c/p\u003e\n\n\u003cp\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/p\u003e\n\n\u003ch3\u003eOut-of-Scope:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eOOS Comcast Subsidiaries\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNBCUniversal\u003c/li\u003e\n\u003cli\u003eSky\n \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOOS Submission Types:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e3rd party endpoints\u003c/li\u003e\n\u003cli\u003eMarketing/Analytics endpoints\u003c/li\u003e\n\u003cli\u003eServer security misconfigurations with no impact (ex. Exposed instances with no sensitive data present) \u003c/li\u003e\n\u003cli\u003eEmail spoofing issues (e.g., SPF, DKIM, DMARC)\u003c/li\u003e\n\u003cli\u003eAutomated scan reports or search engine results (ie, Shodan) without valid proof of concept\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eBanner Grabbing, Scanner Outputs, Password Complexity, User Enumeration, Software version disclosure, Descriptive error messages or headers (e.g. stack traces, application or server errors)\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eAny activity that could disrupt our service (DoS), including but not limited to inundating support services with invalid requests.\u003c/li\u003e\n\u003cli\u003eSelf-Client-side injection (XSS, Angular, Vue, HTML...) and any XSS that requires Flash. Flash is disabled by default in most modern browsers, thus significantly reducing the attack surface and associated risk.\u003c/li\u003e\n\u003cli\u003eCORS without exploitation.\u003c/li\u003e\n\u003cli\u003eWe'll accept notifications of XSS due to Swagger-UI, but they're not eligible for bounty. It will be considered as P5 Informational. \u003c/li\u003e\n\u003cli\u003eThe customer leaked credentials found in Darkweb or any OSINT tools.\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affect users of outdated or unpatched browsers\u003c/li\u003e\n\u003cli\u003eExposed credentials that are either no longer valid, or do not pose a risk to an in-scope asset.\u003c/li\u003e\n\u003cli\u003eRate limiting issues on non-authentication endpoints/Anti-Automation.\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact, or where the only impact is exhausting of API quotas\u003c/li\u003e\n\u003cli\u003eProtocol-specific flaws and open ports or services without an accompanying proof-of-concept demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eSSL/TLS protocol scan reports reporting purported vulnerable protocol versions or handshakes\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy, HttpOnly or Secure flags on cookies.\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated.\u003c/li\u003e\n\u003cli\u003eTheoretical security issues without any POC\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOOS Activity Types:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eLoad Testing (DoS, DDoS, wireless jamming, etc.)\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003eTabnabbing.\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.\u003c/li\u003e\n\u003cli\u003eAccount lockout, login, or forgot password page brute force\u003c/li\u003e\n\u003cli\u003ePublicly accessible login panels unless proven security Impact.\u003c/li\u003e\n\u003cli\u003eSocial engineering attacks, including those targeting or impersonating internal employees by any means (e.g. customer service chat features, social media, personal domains, etc.)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g., Stack Traces, application, or server errors) without proof of vulnerability or risk\u003c/li\u003e\n\u003cli\u003eSubmissions for 3rd party code where Comcast is not responsible for the code.\u003c/li\u003e\n\u003cli\u003eBe a current employee of Comcast or its affiliates or subsidiaries or an employee who has left Comcast or its affiliates or subsidiaries within the past 12 months.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you are unsure about a finding's eligibility please feel free to clarify with the team by sending an email to SecurityDefectReporting@comcast.com.\u003c/p\u003e\n\n\u003ch3\u003eHardware Out Of Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eHardware submissions can be submitted on the \u003ca href=\"https://bugcrowd.com/xfinity-home\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eXfinity Home\u003c/a\u003e program. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRules:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDo not access, impact, destroy or otherwise negatively impact any residential or business customers, or customer data in any way\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eDo not test against any customer account without explicit permission\u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty.\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g. phishing, vishing, smishing) is prohibited.\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we only award the first report that was received (provided that it can be fully reproduced) including security issues that have already been identified internally.\u003c/li\u003e\n\u003cli\u003eDo exercise caution when testing to avoid negative impact to data or services.\u003c/li\u003e\n\u003cli\u003eDo abide by these Program Terms\u003c/li\u003e\n\u003cli\u003eDo be patient \u0026amp; make a good faith effort to provide clarifications to any questions we may have about your submission.\u003c/li\u003e\n\u003cli\u003eDo stop whenever you are unsure if your test case may cause, or have caused, destructive data or systems damage with testing a vulnerability; report your initial finding(s) and request authorization to continue testing\n \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eN-Day Policy:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2024, we would consider it in-scope on 01/31/2024\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eIf you believe a vulnerability is particularly sensitive, you may use our PGP key to encrypt your report. \u003c/p\u003e\n\n\u003ch3\u003ePGP Key:\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e-----BEGIN PGP PUBLIC KEY BLOCK-----\n\nmQINBGBeISUBEAC0HSrden41OvU/JV6TbyZ0vCrQrx2keOsCeX0I524BrQbQP/3d\nYLfDCZjaq0U2ZLwV+A/Mu8O+LEqKffOqyBEVCUVyh1Zjkmkp+Jk/FomaEwGj2KYD\nG5iyw0j+Cuu9S1HMrKozOJCGuJ3Aq9qn38n8vLy3spsnCIiKQpJMnYBAzKwDLuO+\n2JrQ7vpZ2ytW63mLcouQ9cKmA4W5OlD6gm7Fd63KYF7g+toxHw22ZXDT01fqAA9n\nzIOyoLZQcLMXAfddQuRklji65/cGhtPIVsBs2ZV9xJnn50VVvfc14P22nK9bZgf0\nXoeBAL8LB+f7VIVTD/+X5ToA1BiFATbivxX3dZZwzGBMxROyFpMU2RCXwZj0NItj\n/YfO4DnG2K77WF9XKpeqt+D/KaV9WXd91GxTJgbjY7GRsGPEjLyGqAAZAvmBdO1p\n+Bc2cxIiQ9yhceVfreUOdNPwp5O1p9Z8NN48cM6J1mrm4473OqIm71BoWaoh2+wn\nUpwPtvQ95ZFSrPrDa9MNRieGB4/zGQkDCQegOFFD1uVF477ft8I0tNUaSc/Ixwpp\nGj9ijY69Ra4I66CJGtGQ79VZ1xpML8RVROTKdbh9hvqBS1/pJiGBUtiPNg5iubvS\nPwmLcwowA6nRU3EYj+jMmje1pEHmcgcu7oMzaWH93EdFEzl1Av4kjnC4jwARAQAB\ntF1Db21jYXN0IFByb2R1Y3QgU2VjdXJpdHkgSW5jaWRlbnQgUmVzcG9uc2UgVGVh\nbSAoUFNJUlQpIDxzZWN1cml0eWRlZmVjdHJlcG9ydGluZ0Bjb21jYXN0LmNvbT6J\nAk4EEwEIADgWIQQ/lltQ7aGclNQZCAinTPOe0kWI8gUCYF4hJQIbAwULCQgHAgYV\nCgkICwIEFgIDAQIeAQIXgAAKCRCnTPOe0kWI8uIOD/sHfn9sMRQYlzcCntyXA/jy\nmgkh2IdwNxOw5wG48m771AR1VFNr54dY3AgK74xPcFsiT6FUyMKrp72weyv/7/BW\nvOh3M2ff9VaZjWeN/L96I3mfHkzoyQ19vDhtc9MtXnZrybV8SvWFyOO0Ziu6gNSl\nygBo4GjBIkAL32uRmqcyoUZTJJdDpLAM/m76lodEQ/ekC5JmJADOdK+BmVh4rJ4H\nbx8Uu+SseTQ0XjccqKYu+T4OxtgqmCLc2gvLpJH72XWDU0iKOyFW1BL4rqh2RTCj\nrn5xEYm3RBVfHjN+z/REuyNwcxcR0dqk5h9903XsYELIQO/tHyBRGxX3HKs+R0Sk\nGYLe/scyoETE91DnZSPrt3c3SrwOur5E8V0yNhGbADYwD6CVVPvIZcdUjusXFdjD\nKT/JfSU6MCqAD70CwBTIUcEobw22C0sGQuEO5ayC3EtdbYvcoAMKU1+TyYzJFPif\nGeQ+KU1Q94Mnc3uh9/nTL+w54IcYm4SzkTGOYqTQPYgdnlkV+kx14iBLfI54QmZS\nYrfY1cqb564W8bDtis9JLRm3yJ2a2q8bCadkuSGpJ3dM6cAYXtTSQeSTiWt3L3Ri\nAu6i2iimUF+TxMfIxUdwRsApTOBBGIDY4EPzWSFH8+Cb3SXYBAm6Bv5KXSplnEbg\nv5z7jnChE2TtUDQ6LM7bF7kCDQRgXiElARAAuPg110eFje7iJ+CWF3YPYlWydzt4\n3syp0tzD+FNx22eiFxJufLONxSLBjpyFcRxixsQtGF1DV/88Ois1brDBkp7kAdpd\nX1c+ESBmqOXTsSy6/YCeD9kChzViS6T+9qUbJLLPG0GFclOrheLumh1RrrO5XRQd\nj+xcF0g/3oYZrWwUFfGHg0RxFp2zi+GODK5Ab7CSsDUkZxDCbGY608Mv/hy3W5GP\npIty+B/i+J4OZJ4FCzgN8jCHNMftI1vMmWFbO4dljWboDf1rNxrbYSdMTCIaSYbi\nGp+K+iucGabhDjo6mCAcjMM9wn/Mo+E/WeRrqHQmYqrSMfrCU/9xZHsbMlIkK+Xj\nCceWmUSNMVhm22qxn6AlQUI9h2jYV4wyYw4uD4vEnkUZiGM//DWCMX6YNNFfU6f/\n4YhIuctq7cv4RHWLW3/c1zHJsNq8r6uaTdYEtYBYWQvYvNj9/aNkuDnjA/TMHEH/\namND500m8HOEs7X6nHLsai/9ZpxUuAlgq+4UVKOX+qG5P+SDbeSUJEqBaCfbC8zE\nSQ5ngSro5et+bOsiC59JfwA/iRlSL5IfJpThIHMoI7SPWvwlQxBwLlfkiDBv0k0e\nw5uw07VDc32WVWg9OIMMwUL5NeMoX535Y6WEZYDPRSTMVy3doUcze+bdWnwzPLbd\ne/DyWjjHzoCwh00AEQEAAYkCNgQYAQgAIBYhBD+WW1DtoZyU1BkICKdM857SRYjy\nBQJgXiElAhsMAAoJEKdM857SRYjy/ZcP/AgQ611ciptmamHlYcwq3EsRTa050UN/\n9/Tw8KzPG5zRIrfgfJKJ90GMOtrAxGCj4Ysbm+oJpRB+M59TOBI+aFw+k4TO4LCq\noaFPPHwLN9pg0Rg5nYnqm0rzCQHYC5iZYbTGnb5GxBW5wLCe+WtkUVLnoEShNEJU\n+Atqs5V34ZmpfzsEqCRlg9vJhodnpwZpYv5iGlqSEL4llfgRfga5P9VKBwjPCklx\nA3A6AXOxXDj1g1mR5DDOfE74aOIS6sB+jN7Fe4wBdF+SCgtuiOk0fr+D8xbMkGRy\nOrsUZZLnu534YreoUGxFnPp4svNp7HFnb1qCUnNdnDwPyeNsL1TKN3C6dqieNlbw\nog60fXUIZ5knYHiHm5BSEfzgVoHrykzq9DUT/fa9xLAxP381chLGTU9jSRDPIPeY\n7YuLDh0pgCqoqQO/QkzsJPE8JyBke7iLFviczlhh31nH9V4dn23c3G5EWgyL3n5u\nS2lEuH14ieCh3Ql4lKD/hNhYEr3DTvrM3OKOgsGFKB+KMmorsT9ePWs2J6gA4dMA\nMQbCp6sSvxSM/lGKCZSgyRsuuWoWKRTqT7MhIhmea3AbyG5rzqLqw+aMGRiY3Uuc\n6OwtW8m2ieGl4AyTUvfsIg+iE+al8FXAEFoN2rxtUFZvc8elpvSe6qkLxEAaSt3O\ng6h+SklSCYsx\n=Lfos\n-----END PGP PUBLIC KEY BLOCK-----\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"a67fead4-29fa-43cd-b9e2-511ef71b2dd1","name":"███████████████","targets":[{"id":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f","uri":null,"name":"██████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5cbee7f3-4cfa-4d3d-b2c0-2240aa777adf","sortOrder":0},"sortOrder":0,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7d6c4369-fa06-4dd9-b2ec-09e1146d413f"}],"recentChangeFlags":null},{"id":"3e379a92-d4de-48ee-b7b6-8d4ee048a235","uri":null,"name":"█████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ae212c71-fce8-42ba-bedb-46aadf686755","sortOrder":0},"sortOrder":0,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"3e379a92-d4de-48ee-b7b6-8d4ee048a235"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"3e379a92-d4de-48ee-b7b6-8d4ee048a235"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3e379a92-d4de-48ee-b7b6-8d4ee048a235"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"3e379a92-d4de-48ee-b7b6-8d4ee048a235"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"3e379a92-d4de-48ee-b7b6-8d4ee048a235"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3e379a92-d4de-48ee-b7b6-8d4ee048a235"}],"recentChangeFlags":null},{"id":"76941fb1-3bc8-420b-8854-038afe19f4b9","uri":null,"name":"█████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e60f1886-1433-4282-9b35-0b9c72ab258f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"76941fb1-3bc8-420b-8854-038afe19f4b9"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c215e7b0-7498-435a-8941-6cc186402249","p1MaxCents":550000,"p1MinCents":350000,"p2MaxCents":250000,"p2MinCents":150000,"p3MaxCents":60000,"p3MinCents":25000,"p4MaxCents":25000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":3500,"max":5500},"2":{"min":1500,"max":2500},"3":{"min":250,"max":600},"4":{"min":50,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"55a6ce5d-17e7-4b33-97f5-83bcf318a9a1","name":"█████████████████","targets":[{"id":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f","uri":null,"name":"███████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cbf65a2c-916d-4439-b9ab-e3839e0a74a0","sortOrder":0},"sortOrder":0,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9894c7b5-4cd1-41b4-b0b0-26bf055a895f"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"8b81bb13-31c2-4aa5-a6a5-e9fa29ba125e","p1MaxCents":275000,"p1MinCents":175000,"p2MaxCents":125000,"p2MinCents":75000,"p3MaxCents":30000,"p3MinCents":12500,"p4MaxCents":12500,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":1750,"max":2750},"2":{"min":750,"max":1250},"3":{"min":125,"max":300},"4":{"min":50,"max":125},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"b0441c28-d738-48b2-a773-931172fda74f","name":"████████████","targets":[{"id":"9a4760ef-ec5b-48f3-b447-eb4e0658102b","uri":null,"name":"█████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"08bb51c0-0471-4f73-b325-461b19479c23","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9a4760ef-ec5b-48f3-b447-eb4e0658102b"}],"recentChangeFlags":null},{"id":"55a663b4-743f-4d21-bd23-1d892b1befe6","uri":null,"name":"████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d0e98859-55de-430c-bbe8-820365e3da9a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"55a663b4-743f-4d21-bd23-1d892b1befe6"}],"recentChangeFlags":null},{"id":"0cabf90a-be7c-4940-9183-07b88de7ff81","uri":null,"name":"█████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7b0db5a4-8472-41a6-bcf7-f12be8980b0e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0cabf90a-be7c-4940-9183-07b88de7ff81"}],"recentChangeFlags":null},{"id":"b60596b0-326b-49d0-a7c9-4c37bb56fb8a","uri":null,"name":"██████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1c77131b-3bdf-4d18-bb27-ee39a1df24d3","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a959e3c5-2e5a-4044-85e3-574da0f4bd95","uri":null,"name":"█████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c452c03f-46fc-46c2-a3a2-152798eb232d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3a4c22c7-8e0c-4df6-a7d2-3680d0d2836c","uri":null,"name":"█████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5bb7b51f-db7b-4004-8ac5-9e661f634cbc","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"0327b50d-f28c-4420-92f3-e0a9a0417c73","uri":null,"name":"█████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"85447c53-ddaf-4477-b255-4ef67127d23c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"ac92e041-d762-4f03-9446-c9fd52e33cf2","uri":null,"name":"███████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a529331e-394a-4de5-8c91-eb31522f06b9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"37bb5ecf-d04c-4665-ad24-83db479d7857","uri":null,"name":"█████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"49fd0431-efcc-4e76-aebb-639e2921f6f0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"cdcf5df3-0f55-44ac-aa4f-a900e3c346de","uri":null,"name":"███████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"765b2c00-7a6b-47f8-83d9-b2e8de3e1f01","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5a925beb-9e76-40e4-a2c3-434a7ff5cf05","uri":null,"name":"██████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a7e228db-7da7-46ae-a369-2733486c0e94","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"974d5207-f23c-4f00-916e-0c777caa9174","uri":null,"name":"██████████████","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"31805816-27a0-4830-9266-91ce9742c5ba","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"842ec7b2-2b4d-40bc-ad7e-69b991111363","uri":null,"name":"█████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"44f1a57e-1cbb-4e5c-a1cf-0193064b8c61","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a42c4b0a-8cba-4eaa-9d68-529289477980","uri":null,"name":"███","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"38db10a9-8205-4541-9895-952bd105dde7","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"01cdd1f7-8224-4d95-8302-427327f5c10b","uri":null,"name":"█████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"64cb65e3-e7b2-4af5-a163-80404c603356","sortOrder":14},"sortOrder":14,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"01cdd1f7-8224-4d95-8302-427327f5c10b"}],"recentChangeFlags":null},{"id":"01474e9f-2345-42f9-a86f-c87f15b39335","uri":null,"name":"████████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2d749d0a-97b4-4bc3-98d1-2498654e4d6f","sortOrder":15},"sortOrder":15,"tags":null,"recentChangeFlags":null},{"id":"25ebaf19-3619-46a1-a72f-c0bda2d904a1","uri":null,"name":"███████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1ab2224c-0509-42cd-ab3e-dcb078f62f07","sortOrder":16},"sortOrder":16,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"25ebaf19-3619-46a1-a72f-c0bda2d904a1"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"███████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"21ec57ac-a854-4a75-bcb2-473dd4cd2b68","code":"comcast-mbb","state":"in_progress_paused","endsAt":null,"bountyId":"3e71727a-e729-48ff-85e3-bdebac80ec9a","startsAt":"2022-01-20T20:35:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/605d/97ab/be55d53b/3b8b67094243191dc0132258430846b4_comcast.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Hello Researchers,\n\nThank you for your continued engagement with our programs and for helping us strengthen the security of our products and services.\n\nDue to a significant increase in recent submissions, our team is currently reviewing a higher than normal volume of reports. To ensure we provide the level of attention and responsiveness that researchers deserve, we have decided to temporarily pause new submissions for our Bug Bounty programs while we work through the existing queue.\n\nWhat this means:\n\n- The Xfinity and Xfinity Home Bug Bounty programs will temporarily stop accepting new submissions.\n\n- Our Vulnerability Disclosure Program (VDP) remains open and available for reporting security issues. If you discover a vulnerability during this period, please continue to report it through the VDP.\n\n- Researchers with reports currently under review will continue to receive updates throughout the triage and remediation process.\n\n- Eligible reports that have already been submitted will continue through our normal triage, validation, and reward processes.\n\nThis pause is intended to help us improve responsiveness and ensure a high-quality experience for researchers who currently have reports under review.\n\nWe will share additional updates as they become available.\n\nCheers!\n\nComcast PSIRT","lastTransitionAt":"2026-07-13T17:53:39.205Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/comcast-mbb","changelogs":"/engagements/comcast-mbb/changelog","submissions":null,"announcements":"/engagements/comcast-mbb/announcements","hallOfFame":"/engagements/comcast-mbb/hall_of_fames","crowdstream":"/engagements/comcast-mbb/crowdstream"},"announcementsCount":19,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=comcast-mbb\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/comcast-mbb/engagement_subscribers","engagementChangelogsUrl":"/engagements/comcast-mbb/changelog","publishedAt":"2026-07-13T17:53:39.238Z","engagementChangelogUrl":"/engagements/comcast-mbb/changelog/f1b3e165-6a70-418d-9df3-180f38f07907","createUserFeedbacksUrl":"/engagements/comcast-mbb/feedbacks","engagementCrowdstreamUrl":"/engagements/comcast-mbb/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}