{"id":"7d76e69b-319e-4db6-a9a8-21d03297eeab","engagementId":"c0cc318a-14ec-4f74-801e-0cec2e77ac26","data":{"brief":{"id":"9813db5b-5bdc-4595-9cbd-9cd0f1112a37","name":" Comcast Xfinity Vulnerability Disclosure Program","tagline":"Digital Cable TV, Internet and Phone for Residential and Business Services","description":"\u003cp\u003eOur Vulnerability Disclosure Program aims to encompass all the technologies, products, and services that Comcast Xfinity and Comcast Business provides. \u003c/p\u003e\n\n\u003cp\u003eAll endpoints called by these services and applications are in-scope. If you are unsure if something is owned or maintained by us, please let us know and we will make a best effort to determine if we can assist.  \u003c/p\u003e\n\n\u003cp\u003eAll severities are not eligible for monetary rewards at this time.  \u003c/p\u003e\n\n\u003cp\u003eComcast provides Xfinity Internet, TV, wireless, home automation, and more to tens of millions of residential customers, in addition to Comcast Business services to enterprise and small business customers. With so many devices and services in homes and businesses, it has never been more important to ensure the security of those products while striving to deliver an experience that is simple, elegant and powerful. With this in mind, we remain committed to working with security researchers and alongside the security community, and will maintain trust, respect, and transparency that aligns with our commitment to security and privacy.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Comcast not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Comcast, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003ch3\u003eOut-of-Scope:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eOOS Comcast Subsidiaries\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNBCUniversal\u003c/li\u003e\n\u003cli\u003eSky\n \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOOS Submission Types:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e3rd party endpoints\u003c/li\u003e\n\u003cli\u003eMarketing/Analytics endpoints\u003c/li\u003e\n\u003cli\u003eServer security misconfigurations with no impact (ex. Exposed instances with no sensitive data present) \u003c/li\u003e\n\u003cli\u003eEmail spoofing issues (e.g., SPF, DKIM, DMARC)\u003c/li\u003e\n\u003cli\u003eAutomated scan reports or search engine results (ie, Shodan) without valid proof of concept\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated.\u003c/li\u003e\n\u003cli\u003eSelf-Client-side injection (XSS, Angular, Vue, HTML...) and any XSS that requires Flash. Flash is disabled by default in most modern browsers, thus significantly reducing the attack surface and associated risk.\u003c/li\u003e\n\u003cli\u003eCORS without exploitation.\u003c/li\u003e\n\u003cli\u003eWe'll accept notifications of XSS due to Swagger-UI, but they're not eligible for bounty. It will be considered as P5 Informational. \u003c/li\u003e\n\u003cli\u003eExposed credentials that are either no longer valid, or do not pose a risk to an in-scope asset.\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact, or where the only impact is exhausting of API quotas\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affect users of outdated or unpatched browsers\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g., Stack Traces, application, or server errors) without proof of vulnerability or risk\u003c/li\u003e\n\u003cli\u003eSubmissions for 3rd party code where Comcast is not responsible for the code.\u003c/li\u003e\n\u003cli\u003eSSL/TLS protocol scan reports reporting purported vulnerable protocol versions or handshakes\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy, HttpOnly or Secure flags on cookies.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOOS Activity Types:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eLoad Testing (DoS, DDoS, wireless jamming, etc.)\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eBanner Grabbing, Scanner Outputs, Password Complexity, User Enumeration, Software version disclosure, Descriptive error messages or headers (e.g. stack traces, application or server errors)\u003c/li\u003e\n\u003cli\u003eTabnabbing.\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.\u003c/li\u003e\n\u003cli\u003eAccount lockout, login, or forgot password page brute force\u003c/li\u003e\n\u003cli\u003eRate limiting issues on non-authentication endpoints/Anti-Automation.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePublicly accessible login panels unless proven security Impact.\u003c/li\u003e\n\u003cli\u003eAny activity that could disrupt our service (DoS), including but not limited to inundating support services with invalid requests.\u003c/li\u003e\n\u003cli\u003eThe customer leaked credentials found in Darkweb or any OSINT tools.\u003c/li\u003e\n\u003cli\u003eSocial engineering attacks, including those targeting or impersonating internal employees by any means (e.g. customer service chat features, social media, personal domains, etc.)\u003c/li\u003e\n\u003cli\u003eBe a current employee of Comcast or its affiliates or subsidiaries or an employee who has left Comcast or its affiliates or subsidiaries within the past 12 months.\u003c/li\u003e\n\u003cli\u003eProtocol-specific flaws and open ports or services without an accompanying proof-of-concept demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eTheoretical security issues without any POC\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eHardware Out Of Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhysical tampering of the device (I/O devices such as USB, SIM, and SD card slots are in scope)\u003c/li\u003e\n\u003cli\u003eSubmissions that require an attacker to physically open the case, including removing screws or breaking plastic casing (open chassis) to gain access to the internal hardware of a device.\u003c/li\u003e\n\u003cli\u003eVulnerabilities in pre-release product versions (e.g., Beta, Release candidate).\u003c/li\u003e\n\u003cli\u003eVulnerabilities in product versions are no longer under active support.\u003c/li\u003e\n\u003cli\u003eVulnerabilities are already known to Comcast. However, if you are the first external security researcher to identify and report a previously known vulnerability, you may still be eligible for a bounty award.\u003c/li\u003e\n\u003cli\u003eSubmissions that utilize third-party websites or tools for cracking or validating secrets, passwords, keys or tokens.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eIP address\u003c/h3\u003e\n\n\u003cp\u003ePlease provide your IP address in the report while submitting the P1/P2 finding. \u003c/p\u003e\n\n\u003ch3\u003eCustom User-Agent Header\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior:\u003c/p\u003e\n\n\u003cp\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/p\u003e\n\n\u003ch3\u003eRules:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not access, impact, destroy or otherwise negatively impact any residential or business customers, or customer data in any way\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not test against any customer account without explicit permission\u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty.\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g. phishing, vishing, smishing) is prohibited.\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we only award the first report that was received (provided that it can be fully reproduced) including security issues that have already been identified internally.\u003c/li\u003e\n\u003cli\u003eDo exercise caution when testing to avoid negative impact to data or services.\u003c/li\u003e\n\u003cli\u003eDo abide by these Program Terms\u003c/li\u003e\n\u003cli\u003eDo be patient \u0026amp; make a good faith effort to provide clarifications to any questions we may have about your submission.\u003c/li\u003e\n\u003cli\u003eDo stop whenever you are unsure if your test case may cause, or have caused, destructive data or systems damage with testing a vulnerability; report your initial finding(s) and request authorization to continue testing\n \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eN-Day Policy:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2024, we would consider it in-scope on 01/31/2024\n \u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAs an Internet Service Provider, technologies hosted by residential or business customers are considered out-of-scope. These can typically be identified by the FQDN format below.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003e.hfc.comcastbusiness.net\u2028\u003cbr\u003e\n*.hsd1.\u003c/em\u003e.comcast.net\u003c/p\u003e\n\n\u003ch3\u003eBusiness/Residential Customer IP range\u003c/h3\u003e\n\n\u003cp\u003e10.0.0.0/8         \u2028\u003cbr\u003e\n50.128.0.0/12\u2028\u003cbr\u003e\n50.152.0.0/13 \u2028\u003cbr\u003e\n96.201.0.0/16\u2028\u003cbr\u003e\n96.202.128.0/17 \u2028\u003cbr\u003e\n96.203.0.0/16 \u2028\u003cbr\u003e\n172.26.128.0/18\u2028\u003cbr\u003e\n84.112.0.0/13 \u2028\u003cbr\u003e\n184.122.0.0/15\u003cbr\u003e\n \u003cbr\u003e\nIf you are unsure about a finding's eligibility, please feel free to clarify with the team by sending an email to SecurityDefectReporting@comcast.com.\u003cbr\u003e\n \u003c/p\u003e\n\n\u003ch2\u003eAdditional Information:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eFor customers who are experiencing abuse-related issues such as phishing, spam and identity theft, the Customer Security Assurance organization has been established to respond to your issues. Their contact information can be found at our \u003ca href=\"https://internetsecurity.xfinity.com/help/report-abuse/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eReport Abuse page\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWe do not offer accounts or credentials for testing purposes. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eVRT Amendments\u003c/h3\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eVRT Name\u003c/th\u003e\n\u003cth\u003eAdjusted Priority\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eHigh Impact Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP2 -\u0026gt; P3\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eIf you believe a vulnerability is particularly sensitive, you may use our PGP key to encrypt your report. \u003c/p\u003e\n\n\u003ch3\u003ePGP Key:\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e-----BEGIN PGP PUBLIC KEY BLOCK-----\n\nmQINBGBeISUBEAC0HSrden41OvU/JV6TbyZ0vCrQrx2keOsCeX0I524BrQbQP/3d\nYLfDCZjaq0U2ZLwV+A/Mu8O+LEqKffOqyBEVCUVyh1Zjkmkp+Jk/FomaEwGj2KYD\nG5iyw0j+Cuu9S1HMrKozOJCGuJ3Aq9qn38n8vLy3spsnCIiKQpJMnYBAzKwDLuO+\n2JrQ7vpZ2ytW63mLcouQ9cKmA4W5OlD6gm7Fd63KYF7g+toxHw22ZXDT01fqAA9n\nzIOyoLZQcLMXAfddQuRklji65/cGhtPIVsBs2ZV9xJnn50VVvfc14P22nK9bZgf0\nXoeBAL8LB+f7VIVTD/+X5ToA1BiFATbivxX3dZZwzGBMxROyFpMU2RCXwZj0NItj\n/YfO4DnG2K77WF9XKpeqt+D/KaV9WXd91GxTJgbjY7GRsGPEjLyGqAAZAvmBdO1p\n+Bc2cxIiQ9yhceVfreUOdNPwp5O1p9Z8NN48cM6J1mrm4473OqIm71BoWaoh2+wn\nUpwPtvQ95ZFSrPrDa9MNRieGB4/zGQkDCQegOFFD1uVF477ft8I0tNUaSc/Ixwpp\nGj9ijY69Ra4I66CJGtGQ79VZ1xpML8RVROTKdbh9hvqBS1/pJiGBUtiPNg5iubvS\nPwmLcwowA6nRU3EYj+jMmje1pEHmcgcu7oMzaWH93EdFEzl1Av4kjnC4jwARAQAB\ntF1Db21jYXN0IFByb2R1Y3QgU2VjdXJpdHkgSW5jaWRlbnQgUmVzcG9uc2UgVGVh\nbSAoUFNJUlQpIDxzZWN1cml0eWRlZmVjdHJlcG9ydGluZ0Bjb21jYXN0LmNvbT6J\nAk4EEwEIADgWIQQ/lltQ7aGclNQZCAinTPOe0kWI8gUCYF4hJQIbAwULCQgHAgYV\nCgkICwIEFgIDAQIeAQIXgAAKCRCnTPOe0kWI8uIOD/sHfn9sMRQYlzcCntyXA/jy\nmgkh2IdwNxOw5wG48m771AR1VFNr54dY3AgK74xPcFsiT6FUyMKrp72weyv/7/BW\nvOh3M2ff9VaZjWeN/L96I3mfHkzoyQ19vDhtc9MtXnZrybV8SvWFyOO0Ziu6gNSl\nygBo4GjBIkAL32uRmqcyoUZTJJdDpLAM/m76lodEQ/ekC5JmJADOdK+BmVh4rJ4H\nbx8Uu+SseTQ0XjccqKYu+T4OxtgqmCLc2gvLpJH72XWDU0iKOyFW1BL4rqh2RTCj\nrn5xEYm3RBVfHjN+z/REuyNwcxcR0dqk5h9903XsYELIQO/tHyBRGxX3HKs+R0Sk\nGYLe/scyoETE91DnZSPrt3c3SrwOur5E8V0yNhGbADYwD6CVVPvIZcdUjusXFdjD\nKT/JfSU6MCqAD70CwBTIUcEobw22C0sGQuEO5ayC3EtdbYvcoAMKU1+TyYzJFPif\nGeQ+KU1Q94Mnc3uh9/nTL+w54IcYm4SzkTGOYqTQPYgdnlkV+kx14iBLfI54QmZS\nYrfY1cqb564W8bDtis9JLRm3yJ2a2q8bCadkuSGpJ3dM6cAYXtTSQeSTiWt3L3Ri\nAu6i2iimUF+TxMfIxUdwRsApTOBBGIDY4EPzWSFH8+Cb3SXYBAm6Bv5KXSplnEbg\nv5z7jnChE2TtUDQ6LM7bF7kCDQRgXiElARAAuPg110eFje7iJ+CWF3YPYlWydzt4\n3syp0tzD+FNx22eiFxJufLONxSLBjpyFcRxixsQtGF1DV/88Ois1brDBkp7kAdpd\nX1c+ESBmqOXTsSy6/YCeD9kChzViS6T+9qUbJLLPG0GFclOrheLumh1RrrO5XRQd\nj+xcF0g/3oYZrWwUFfGHg0RxFp2zi+GODK5Ab7CSsDUkZxDCbGY608Mv/hy3W5GP\npIty+B/i+J4OZJ4FCzgN8jCHNMftI1vMmWFbO4dljWboDf1rNxrbYSdMTCIaSYbi\nGp+K+iucGabhDjo6mCAcjMM9wn/Mo+E/WeRrqHQmYqrSMfrCU/9xZHsbMlIkK+Xj\nCceWmUSNMVhm22qxn6AlQUI9h2jYV4wyYw4uD4vEnkUZiGM//DWCMX6YNNFfU6f/\n4YhIuctq7cv4RHWLW3/c1zHJsNq8r6uaTdYEtYBYWQvYvNj9/aNkuDnjA/TMHEH/\namND500m8HOEs7X6nHLsai/9ZpxUuAlgq+4UVKOX+qG5P+SDbeSUJEqBaCfbC8zE\nSQ5ngSro5et+bOsiC59JfwA/iRlSL5IfJpThIHMoI7SPWvwlQxBwLlfkiDBv0k0e\nw5uw07VDc32WVWg9OIMMwUL5NeMoX535Y6WEZYDPRSTMVy3doUcze+bdWnwzPLbd\ne/DyWjjHzoCwh00AEQEAAYkCNgQYAQgAIBYhBD+WW1DtoZyU1BkICKdM857SRYjy\nBQJgXiElAhsMAAoJEKdM857SRYjy/ZcP/AgQ611ciptmamHlYcwq3EsRTa050UN/\n9/Tw8KzPG5zRIrfgfJKJ90GMOtrAxGCj4Ysbm+oJpRB+M59TOBI+aFw+k4TO4LCq\noaFPPHwLN9pg0Rg5nYnqm0rzCQHYC5iZYbTGnb5GxBW5wLCe+WtkUVLnoEShNEJU\n+Atqs5V34ZmpfzsEqCRlg9vJhodnpwZpYv5iGlqSEL4llfgRfga5P9VKBwjPCklx\nA3A6AXOxXDj1g1mR5DDOfE74aOIS6sB+jN7Fe4wBdF+SCgtuiOk0fr+D8xbMkGRy\nOrsUZZLnu534YreoUGxFnPp4svNp7HFnb1qCUnNdnDwPyeNsL1TKN3C6dqieNlbw\nog60fXUIZ5knYHiHm5BSEfzgVoHrykzq9DUT/fa9xLAxP381chLGTU9jSRDPIPeY\n7YuLDh0pgCqoqQO/QkzsJPE8JyBke7iLFviczlhh31nH9V4dn23c3G5EWgyL3n5u\nS2lEuH14ieCh3Ql4lKD/hNhYEr3DTvrM3OKOgsGFKB+KMmorsT9ePWs2J6gA4dMA\nMQbCp6sSvxSM/lGKCZSgyRsuuWoWKRTqT7MhIhmea3AbyG5rzqLqw+aMGRiY3Uuc\n6OwtW8m2ieGl4AyTUvfsIg+iE+al8FXAEFoN2rxtUFZvc8elpvSe6qkLxEAaSt3O\ng6h+SklSCYsx\n=Lfos\n-----END PGP PUBLIC KEY BLOCK-----\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e2c401ae-c2be-4720-82bd-46cef6747bfb","name":"Primary Targets","targets":[{"id":"01cdd1f7-8224-4d95-8302-427327f5c10b","uri":null,"name":"*.sys.comcast.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4a7dd68b-2eda-4c2a-a148-52b5f941da77","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"01cdd1f7-8224-4d95-8302-427327f5c10b"}],"recentChangeFlags":null},{"id":"ad396704-10f3-4801-aacd-7db512478fde","uri":"https://business.comcast.com/account","name":"https://business.comcast.com/account","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1b16a01e-bdc5-42c8-8e7a-7fd5081063a6","sortOrder":0},"sortOrder":0,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"ad396704-10f3-4801-aacd-7db512478fde"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"ad396704-10f3-4801-aacd-7db512478fde"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"ad396704-10f3-4801-aacd-7db512478fde"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"ad396704-10f3-4801-aacd-7db512478fde"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"ad396704-10f3-4801-aacd-7db512478fde"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"ad396704-10f3-4801-aacd-7db512478fde"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ad396704-10f3-4801-aacd-7db512478fde"}],"recentChangeFlags":null},{"id":"400e272e-8054-41fc-b08a-973726075367","uri":null,"name":"TV - Xfinity hardware and services","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8df6946f-f078-46db-9fc6-33eaa443c2cd","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"400e272e-8054-41fc-b08a-973726075367"}],"recentChangeFlags":null},{"id":"55c98427-8a10-4ac6-a9de-1d3bd4e8f10d","uri":null,"name":"Flex - Xfinity hardware and services","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4f5820c2-a6dc-4158-ad82-20dc465e7dda","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"55c98427-8a10-4ac6-a9de-1d3bd4e8f10d"}],"recentChangeFlags":null},{"id":"5c210f2e-ca65-4c41-851c-f269f4080fd5","uri":null,"name":"Voice - Hardware and service","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"de84eb89-64bf-4501-a645-3c0cc142a3c5","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"5c210f2e-ca65-4c41-851c-f269f4080fd5"}],"recentChangeFlags":null},{"id":"c336b7f8-ea68-48c8-884b-ef95a8f16e31","uri":"https://www.xfinity.com/apps","name":"Mobile Apps\tiOS and Android","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"21e86af1-7e9f-4d99-844e-eafa56442e14","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"c336b7f8-ea68-48c8-884b-ef95a8f16e31"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"004f0a9a-0e25-49d6-9469-d4d18525d5b6","name":"Out of Scope","targets":[{"id":"f1269f14-14ce-426d-8cc5-8c639397473f","uri":"https://www.comcastbiz.net/","name":"Comcastbiz.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"39a9768c-f726-4f55-8033-799ef20464b9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"789e5ac4-fe18-41d3-8c0f-0146779fe449","attachmentPath":"https://bugcrowd.com/engagements/comcastvdp/attachments/789e5ac4-fe18-41d3-8c0f-0146779fe449","name":"image-2024-03-05T14:09:54.538Z.png","filename":"image-2024-03-05T14:09:54.538Z.png","description":null,"icon":"fileImage","size":168600,"sizeLabel":"165 KB","uploadedAt":"1 Sep 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/comcastvdp/attachments/789e5ac4-fe18-41d3-8c0f-0146779fe449"},{"id":"5bebcf8d-3586-46b7-8afd-c5cf751040a3","attachmentPath":"https://bugcrowd.com/engagements/comcastvdp/attachments/5bebcf8d-3586-46b7-8afd-c5cf751040a3","name":"image-2024-03-05T14:11:41.675Z.png","filename":"image-2024-03-05T14:11:41.675Z.png","description":null,"icon":"fileImage","size":8785,"sizeLabel":"8.58 KB","uploadedAt":"1 Sep 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/comcastvdp/attachments/5bebcf8d-3586-46b7-8afd-c5cf751040a3"},{"id":"10c28294-f85e-43ed-92b1-0f3c53a64ba5","attachmentPath":"https://bugcrowd.com/engagements/comcastvdp/attachments/10c28294-f85e-43ed-92b1-0f3c53a64ba5","name":"image-2024-03-05T14:10:32.790Z.png","filename":"image-2024-03-05T14:10:32.790Z.png","description":null,"icon":"fileImage","size":169165,"sizeLabel":"165 KB","uploadedAt":"1 Sep 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/comcastvdp/attachments/10c28294-f85e-43ed-92b1-0f3c53a64ba5"}],"engagement":{"id":"c0cc318a-14ec-4f74-801e-0cec2e77ac26","code":"comcastvdp","state":"in_progress","endsAt":null,"bountyId":"55c524cc-1a60-4fac-9ab2-46ab3d05a71d","startsAt":"2018-05-04T00:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/73d8/3094/c9ca7058/382e5cddd922bd653ca8f6639df5c2ba_Comcast_logo_2012.png","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-05-04T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/comcastvdp","changelogs":"/engagements/comcastvdp/changelog","submissions":null,"announcements":"/engagements/comcastvdp/announcements","hallOfFame":"/engagements/comcastvdp/hall_of_fames","crowdstream":"/engagements/comcastvdp/crowdstream"},"announcementsCount":14,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/comcastvdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=comcastvdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/comcastvdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/comcastvdp/changelog","publishedAt":"2026-08-10T19:35:03.297Z","engagementChangelogUrl":"/engagements/comcastvdp/changelog/7d76e69b-319e-4db6-a9a8-21d03297eeab","createUserFeedbacksUrl":"/engagements/comcastvdp/feedbacks","engagementCrowdstreamUrl":"/engagements/comcastvdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}