{"id":"8e83af01-4187-4573-a7ea-339b93ed6bc5","engagementId":"3513b617-9754-42a9-9fee-73115852ee19","data":{"brief":{"id":"edaec9ec-dea1-4a27-950c-e7efd5901080","name":"Department of Homeland Security: Vulnerability Disclosure Program","tagline":"Report DHS Vulnerabilities! ","description":"\u003cp\u003eDHS has a unique information and communications technology footprint that is tightly interwoven and globally deployed. Many DHS technologies are deployed in critical infrastructure systems and, to varying degrees, support ongoing homeland security operations; the proper functioning of DHS systems and applications can have a life-or-death impact on DHS personnel and international allies and partners of the United States.\u003c/p\u003e\n\n\u003cp\u003eOur information systems provide critical services in support of the widespread, critical missions of DHS. Maintaining the security of our networks is a high priority at DHS. Ultimately, our network security ensures that we can accomplish our missions and contribute to the success of the individuals who contribute to the mission success.\u003c/p\u003e\n\n\u003cp\u003eDHS recognizes that security researchers regularly contribute to the work of securing organizations and the Internet as a whole. Therefore, DHS invites reports of any vulnerabilities discovered on internet-accessible DHS information systems, applications, and websites [1]. Information submitted to DHS under this policy will be used for defensive purposes – to mitigate or remediate vulnerabilities in our networks. This program upholds the DHS motto “See Something – Say Something” in the virtual environment by positively engaging with and establishing a communication loop between researchers and DHS.\u003c/p\u003e\n\n\u003cp\u003eHereinafter, researcher [2] may be referred to as “you” or “your” and DHS may be interchangeably used in conjunction with or alternatively referenced as “we”, “our”, or “us”.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003eAn example of the vulnerability report would include a detailed summary, including:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eType of vulnerability\u003c/li\u003e\n\u003cli\u003eIP Address or hostname\u003c/li\u003e\n\u003cli\u003eDescription of vulnerability\u003c/li\u003e\n\u003cli\u003eInstructions to replicate\u003c/li\u003e\n\u003cli\u003ePotential impact to system/site\u003c/li\u003e\n\u003cli\u003eRecommended remediation actions\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eGUIDELINES\u003c/h2\u003e\n\n\u003cp\u003eYou MUST read and agree to abide by the guidelines in this policy for conducting security research and disclosure of vulnerabilities or indicators of vulnerabilities related to DHS information systems.  We will presume you are acting in good faith when you discover, test, and submit reports of vulnerabilities [3] or indicators of vulnerabilities in accordance with these guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou MAY [4] test internet-accessible DHS information systems to detect a vulnerability or identify a n indicator related to a vulnerability for the sole purpose of providing DHS information about such vulnerability.\u003c/li\u003e\n\u003cli\u003eYou MUST avoid harm to DHS information systems and operations.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT exploit any vulnerability beyond the minimal amount of testing required to prove that the vulnerability exists or to identify an indicator related to that vulnerability.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT intentionally access the content of any communications, data, or information transiting or stored on DHS information system(s) – except to the extent that the information is directly related to a vulnerability and the access is necessary to prove that the vulnerability exists.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT exfiltrate any data under any circumstances.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT intentionally compromise the privacy or safety of DHS personnel (e.g., civilian employees) or any legitimate third parties.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT intentionally compromise the intellectual property or other commercial or financial interests of any DHS personnel or entities or any legitimate third parties.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT disclose any details of any extant DHS information system vulnerability or indicator of vulnerability to any party not already aware at the time the report is submitted to DHS.\u003c/li\u003e\n\u003cli\u003eIn the event that you find a vulnerability in a DHS information system consequent to a vulnerability in a generally available product, you MAY report the product vulnerability to the affected vendor or a third party vulnerability coordination service in order to enable the product to be fixed.\u003c/li\u003e\n\u003cli\u003eYou MAY disclose to the public the prior existence of vulnerabilities already fixed by DHS, potentially including details of the vulnerability, indicators of vulnerability, or the nature (but not content) of information rendered available by the vulnerability. If you choose to disclose, you should do so in consultation with DHS.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT disclose any incidental proprietary data revealed during testing or the content of information rendered available by the vulnerability to any party not already aware at the time the report is submitted to DHS.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT cause a denial of any legitimate services in the course of your testing.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT conduct social engineering in any form of DHS personnel or contractors.\u003c/li\u003e\n\u003cli\u003eYou SHOULD strive to submit high-quality reports.\u003c/li\u003e\n\u003cli\u003eYou MUST NOT submit a high-volume of low-quality reports.\u003c/li\u003e\n\u003cli\u003eYou MUST comply with all applicable Federal, State, and local laws in connection with security research activities or other participation in this vulnerability disclosure program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf at any point you are uncertain of whether to proceed with testing, please contact our team at Vulnerability.Disclosure.Prog@hq.dhs.gov.\u003c/p\u003e\n\n\u003ch2\u003ePARTICIPANT EXPECTATIONS\u003c/h2\u003e\n\n\u003cp\u003eWe take every disclosure seriously, and very much appreciate your efforts.  We are committed to coordinating with you as openly and expeditiously as possible. The contents of information provided in the reports and follow-up communications are processed and stored on a U.S. Government information system. You can expect us to do the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe SHALL investigate every reported vulnerability and strive to ensure that appropriate steps are taken to mitigate risk and remediate reported vulnerabilities.\u003c/li\u003e\n\u003cli\u003eIf you opt to provide your contact information, our security team MAY contact you for further information.\u003c/li\u003e\n\u003cli\u003eWe SHALL, to the best of our ability, validate the existence of the vulnerability.\u003c/li\u003e\n\u003cli\u003eWe MAY disclose to the public the prior existence of vulnerabilities remedied by us, potentially including details of the vulnerability such as the indicators of vulnerability, or the nature (but not content) of information rendered available by the vulnerability.\u003c/li\u003e\n\u003cli\u003eIn the event that we choose to publicly disclose your reported vulnerability we SHALL recognize your contribution as it must pertain to improving our security, the first to report a unique vulnerability, and if your report triggers a code or configuration change.\u003c/li\u003e\n\u003cli\u003eIn the event you report a vulnerability pertaining to a generally available product, we SHALL validate the vulnerability pertaining to the identified product is legitimate and that it is a product used within our environment. After those factors are verified, we MAY report the product vulnerability to the affected vendor or to a third-party vulnerability coordination service.\u003c/li\u003e\n\u003cli\u003eWe SHALL NOT forward your name and contact information to any affected vendors unless otherwise requested by you.\u003c/li\u003e\n\u003cli\u003eWe MAY NOT disclose information provided by any vendor unless the vendor explicitly states to do so.\u003c/li\u003e\n\u003cli\u003eWe SHALL request 30 days for acknowledgement and 90 days for mitigation development, and deployment.\u003c/li\u003e\n\u003cli\u003eWe MAY consult with you and any affected vendors to determine our public disclosure [5] plans of the vulnerability\u003c/li\u003e\n\u003cli\u003eIn cases where a product is affected and the vendor is unresponsive, or fails to establish a reasonable timeframe for remediation, we MAY disclose product vulnerabilities 45 days after the initial contact is made, regardless of the existence or availability of patches or workarounds from affected vendors.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLEGAL / AUTHORIZATION\u003c/h2\u003e\n\n\u003cp\u003eIf you make a good faith effort to conduct your research and disclose vulnerabilities in accordance with the guidelines set forth in this policy, (1) DHS will not recommend or pursue any law enforcement or civil lawsuits related to such activities, and (2) in the event of any law enforcement or civil action brought by any entity other than DHS, DHS will affirm that your research and disclosure activities were conducted pursuant to, and in compliance with, this policy.  This agreement is effective at the time of the form submission on the DHS.gov webpage.\u003c/p\u003e\n\n\u003cp\u003ePlease note that individuals and entities that conduct activities as authorized by this policy and comply with its terms will receive legal protection from criminal or civil liability under section 1030 of title 18, United States Code, and similar laws penalizing unauthorized access to computers.\u003c/p\u003e\n\n\u003cp\u003eDHS does not authorize, permit, or otherwise allow (expressly or implicitly) any person, including any individual, group of individuals, consortium, partnership, or any other business or legal entity to engage in any security research or vulnerability or threat disclosure activity that is inconsistent with this policy or the law. Any activities that are inconsistent with this policy or the law may lead to criminal and/or civil liabilities. Third parties (e.g., any non-DHS entity) may independently determine whether to pursue legal recourse or related. DHS may modify the terms of this policy, or suspend this policy at any time.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e[1] These websites constitute “information systems” as defined by 44 U.S.C. 3502.\u003cbr\u003e\n[2] The term “Researcher” in this document is intended to be consistent with the terms “Finder” and/or “Reporter” as used in ISO/IEC 29147:2014(E) and the CERT® Guide to Coordinated Vulnerability Disclosure, and may be substituted with “you, your”\u003cbr\u003e\n[3] Vulnerabilities throughout this policy may be considered “security vulnerabilities” as defined by Cybersecurity Information Sharing Act of 2015, Pub. L. No. 114-113, § 102: “The term \"security vulnerability\" means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.”\u003cbr\u003e\n[4] The key words \"MUST\", \"MUST NOT\", \"REQUIRED\", \"SHALL\", \"SHALL NOT\", \"SHOULD\", \"SHOULD NOT\", \"RECOMMENDED\",  \"MAY\", and \"OPTIONAL\" in this document are to be interpreted as described in RFC 2119.\u003cbr\u003e\n[5] “Public disclosure” means the release of previously undisclosed information related to a vulnerability by DHS, a vendor, or a researcher to [the public/non-governmental persons or entities] through mediums that include, but are not limited to, official press releases, blogs, social media platforms, email, or other webpages.  We SHALL make our disclosure determinations based on relevant factors, such as: whether the vulnerability has already been publicly disclosed, the severity of the vulnerability, potential impact to critical infrastructure, possible threat to public health and safety, immediate mitigations available, vendor responsiveness and feasibility for creating an upgrade or patch, and vendor estimate of time required for customers to obtain, test, and apply the patch. Active exploitation, threats of an especially serious nature, or situations that require changes to an established standard may result in earlier or later disclosure.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThe Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Platform (VDP Platform) gives agencies the option to use a centrally managed system to intake vulnerability information from and collaborate with the public to improve the security of their internet-accessible systems. CISA has a contract with EnDyna and Bugcrowd, private companies, to manage the platform used by the public to report vulnerability information; CISA exercises general oversight of the program.  CISA does not collect, maintain, use, or disseminate any Personally Identifiable Information (PII) provided to Bugcrowd for the purposes of creating a profile on the website or reporting a vulnerability to agencies other than CISA.  Participating agencies provide their own program vulnerability disclosure policy, setting out the agency’s parameters for vulnerability disclosures, including provisions for collection and use of submitted information. Any submissions of vulnerabilities pertaining to CISA’s own information systems would be governed by the DHS VDP brief.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"d2e91aef-60d7-4047-97c9-3fcc11cbaa7a","name":"In Scope","targets":[{"id":"dc78f024-7b14-4d5a-a362-cccdc682a239","uri":"","name":"*.dhs.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"42dd8b23-e84f-4322-b668-5b147c2af2ef","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"dc78f024-7b14-4d5a-a362-cccdc682a239"}],"recentChangeFlags":null},{"id":"cbde70d5-b969-4499-913f-fc5f36b482e0","uri":"","name":"*.BIOMETRICS.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c725746d-1c47-426c-be9d-1c3d24089a4f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cbde70d5-b969-4499-913f-fc5f36b482e0"}],"recentChangeFlags":null},{"id":"f3e0924c-8fe0-4a5e-b344-31b887dc9ac7","uri":"","name":"*.CBP.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"04bc6c7d-be4e-42f5-a4d1-41192adb9251","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f3e0924c-8fe0-4a5e-b344-31b887dc9ac7"}],"recentChangeFlags":null},{"id":"f201ac1c-01d7-472f-85db-a5fcb00e6e0d","uri":"","name":"*.CISA.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"323d3161-39de-4c82-a189-d275190cb77e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f201ac1c-01d7-472f-85db-a5fcb00e6e0d"}],"recentChangeFlags":null},{"id":"8b92faa6-e3b0-4b95-b21f-7d9214fa8e03","uri":"","name":"*.CPNIREPORTING.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ac7b7cb8-7d13-4732-b8c1-87853e881e33","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8b92faa6-e3b0-4b95-b21f-7d9214fa8e03"}],"recentChangeFlags":null},{"id":"dc421954-17bc-4caa-9812-3538d955428e","uri":"","name":"*.CYBER.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"556ba5d6-e381-4dc6-8640-cf1b9d11f40a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"dc421954-17bc-4caa-9812-3538d955428e"}],"recentChangeFlags":null},{"id":"015a1a3a-0e5c-41e0-8379-9950db774ff3","uri":"","name":"*.CYBERSECURITY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6e5813ef-87d4-4f9f-8de0-aa0b22c1eeb3","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"015a1a3a-0e5c-41e0-8379-9950db774ff3"}],"recentChangeFlags":null},{"id":"3c6e6a49-4705-467a-93bd-13ae65b8ed42","uri":"","name":"*.DISASTERASSISTANCE.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"20f6e7ee-1c63-48de-8abe-c980f32fe905","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3c6e6a49-4705-467a-93bd-13ae65b8ed42"}],"recentChangeFlags":null},{"id":"051ec5ef-bd11-4a24-899f-ac037258f175","uri":"","name":"*.DOTGOV.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bbf12139-f16b-483f-8d59-a0f5185aad49","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"051ec5ef-bd11-4a24-899f-ac037258f175"}],"recentChangeFlags":null},{"id":"1c619027-08fe-4bb9-b9ce-9d9018e4041d","uri":"","name":"*.E-VERIFY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6bc853e9-01ef-49c3-88de-6cf889032d55","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1c619027-08fe-4bb9-b9ce-9d9018e4041d"}],"recentChangeFlags":null},{"id":"a4baa596-dee5-4626-8f53-e6915c154ad4","uri":"","name":"*.EVERIFY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7fd1f935-7c67-433e-937f-9fa0e6e070ed","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a4baa596-dee5-4626-8f53-e6915c154ad4"}],"recentChangeFlags":null},{"id":"c63bf6d0-a205-4b29-a0eb-1f3572308adf","uri":"","name":"*.EVUS.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"997a1275-7637-4e8b-8aa7-00bea36763da","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c63bf6d0-a205-4b29-a0eb-1f3572308adf"}],"recentChangeFlags":null},{"id":"270db579-6d99-49ec-a987-f9dc10c26b79","uri":"","name":"*.FEMA.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8bc8d32e-2c78-4abe-aed1-ddcb9acb5523","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"270db579-6d99-49ec-a987-f9dc10c26b79"}],"recentChangeFlags":null},{"id":"2dd3c402-daa8-4361-8b6e-b1d710b78f2c","uri":"","name":"*.FIRSTRESPONDERTRAINING.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6d02739b-f7d4-4060-8a16-0c40b148d9e5","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2dd3c402-daa8-4361-8b6e-b1d710b78f2c"}],"recentChangeFlags":null},{"id":"e15143d4-7053-4665-97b7-1cad922e6b07","uri":"","name":"*.FLETA.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f3ad033f-ee08-4a74-a23b-b0dc96c78905","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e15143d4-7053-4665-97b7-1cad922e6b07"}],"recentChangeFlags":null},{"id":"97c1c1f1-c3f9-4fd3-8824-8ee6d5cdf7a0","uri":"","name":"*.FLETC.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7f8d2a17-27b2-400f-8704-af343d39218f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"97c1c1f1-c3f9-4fd3-8824-8ee6d5cdf7a0"}],"recentChangeFlags":null},{"id":"c69ebf9d-1ecd-4135-bc06-482eca313056","uri":"","name":"*.FLOODSMART.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3aba4263-3f0b-416c-a8a4-aae5eea83565","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c69ebf9d-1ecd-4135-bc06-482eca313056"}],"recentChangeFlags":null},{"id":"a5efa824-e33a-4213-848b-33ce5440e8f0","uri":"","name":"*.GET.GOV","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dd0abcdd-90b0-433a-83d3-9728a7937759","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a5efa824-e33a-4213-848b-33ce5440e8f0"}],"recentChangeFlags":null},{"id":"95ddc0e0-a2a5-4d87-9c0d-8d41a1366be2","uri":"","name":"*.GLOBALENTRY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a809c9b5-52e0-459d-a5de-e48ffc76f80e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"95ddc0e0-a2a5-4d87-9c0d-8d41a1366be2"}],"recentChangeFlags":null},{"id":"f29e357c-5520-457e-8f1f-7c85c326d69c","uri":"","name":"*.HOMELANDSECURITY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3cc3bc0e-28d5-4994-9df4-4784ae2fadf5","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f29e357c-5520-457e-8f1f-7c85c326d69c"}],"recentChangeFlags":null},{"id":"f4eb1af7-5239-4257-983f-6c391aa3f8e1","uri":"","name":"*.ICE.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"53f6d818-c064-46a7-9c6f-2d2f9c435edc","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f4eb1af7-5239-4257-983f-6c391aa3f8e1"}],"recentChangeFlags":null},{"id":"318a8632-61fc-404c-b2e6-a19ad03ced68","uri":"","name":"*.JUNTOS.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5ef89729-b545-4ee0-b80e-18fcd9085b77","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"318a8632-61fc-404c-b2e6-a19ad03ced68"}],"recentChangeFlags":null},{"id":"c8c45ba9-0ad9-448a-aa68-f2a8fb585066","uri":"","name":"*.LISTO.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"950e0eef-5ce6-4b50-ba66-c05fd1475229","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c8c45ba9-0ad9-448a-aa68-f2a8fb585066"}],"recentChangeFlags":null},{"id":"03a99789-6239-4d2f-8308-d2d7c3b70ea1","uri":"","name":"*.NIC.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"dd69bb5a-a04a-48ff-bf16-0deb189b73f6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"03a99789-6239-4d2f-8308-d2d7c3b70ea1"}],"recentChangeFlags":null},{"id":"029a00df-ce74-400d-a3e9-d66e534e6db9","uri":"","name":"*.NIEM.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2d21ca79-615d-42e2-a7dd-5f59791ec31b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"029a00df-ce74-400d-a3e9-d66e534e6db9"}],"recentChangeFlags":null},{"id":"2816e1b7-1f14-40de-94da-1a3108d00e89","uri":"","name":"*.NMSC.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"97eb92fa-9704-49ff-9d41-001ff913d19d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2816e1b7-1f14-40de-94da-1a3108d00e89"}],"recentChangeFlags":null},{"id":"c07ee1c9-a26b-428c-9ad7-bfaf9a2c8cc1","uri":"","name":"*.POWER2PREVENT.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d4d7a9eb-b7f4-4d5b-9c49-910ed7243f7c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c07ee1c9-a26b-428c-9ad7-bfaf9a2c8cc1"}],"recentChangeFlags":null},{"id":"eaedf944-4eac-414a-935d-281a51c01005","uri":"","name":"*.PREVENTIONRESOURCEFINDER.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"14a32a03-427e-43c9-b029-a301ada634bd","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"eaedf944-4eac-414a-935d-281a51c01005"}],"recentChangeFlags":null},{"id":"6ccd2b95-7f46-48e6-951d-d670d9c636bc","uri":"","name":"*.READY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"265c8659-7486-4fee-b2d1-855af90bd8bc","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6ccd2b95-7f46-48e6-951d-d670d9c636bc"}],"recentChangeFlags":null},{"id":"d03b954b-11f5-45fe-9136-dce959fcad79","uri":"","name":"*.READYBUSINESS.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ffd8a708-3340-4425-94ba-222c1bc69d15","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d03b954b-11f5-45fe-9136-dce959fcad79"}],"recentChangeFlags":null},{"id":"95047815-9656-462e-8420-fa303b748d2a","uri":"","name":"*.SAFETYACT.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8a9eac58-ae46-4feb-8af8-638d7c7cfa88","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"95047815-9656-462e-8420-fa303b748d2a"}],"recentChangeFlags":null},{"id":"e63c356f-62ff-43df-9f5b-440d074bfdea","uri":"","name":"*.SCHOOLSAFETY.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e2711a68-e467-4264-8ace-b5037be254f7","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e63c356f-62ff-43df-9f5b-440d074bfdea"}],"recentChangeFlags":null},{"id":"a4cc6b21-4e9a-4c5a-8f07-836623702660","uri":"","name":"*.SECRETSERVICE.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e71105b3-1556-43d6-9215-23b2631c4d9c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a4cc6b21-4e9a-4c5a-8f07-836623702660"}],"recentChangeFlags":null},{"id":"29e5132b-c69b-4214-8f95-a38270acf38d","uri":"","name":"*.STOPRANSOMWARE.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5b61251b-96f1-4e09-a473-581d4e1c1b90","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"29e5132b-c69b-4214-8f95-a38270acf38d"}],"recentChangeFlags":null},{"id":"927bccf0-c9c4-4370-b3cf-0ce7883bfffd","uri":"","name":"*.TOGETHER.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b65f5802-81fe-4b18-8b7d-b41c148aa57c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"927bccf0-c9c4-4370-b3cf-0ce7883bfffd"}],"recentChangeFlags":null},{"id":"d71cd1cc-38b2-475e-9f19-68c9efdfa377","uri":"","name":"*.TSA.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"426fec1b-3c59-4a74-9fe7-06a9b29a5f11","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d71cd1cc-38b2-475e-9f19-68c9efdfa377"}],"recentChangeFlags":null},{"id":"d7fecb03-44af-4c87-92ff-a25588e2e8ed","uri":"","name":"*.US-CERT.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"95e17003-8039-45e4-a6e6-6ff40c00b38e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d7fecb03-44af-4c87-92ff-a25588e2e8ed"}],"recentChangeFlags":null},{"id":"31ba4fcb-38e1-4cdb-a338-ca09b6a99ef3","uri":"","name":"*.USCG.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4c6466be-2fff-4619-aa60-58e795434eda","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"31ba4fcb-38e1-4cdb-a338-ca09b6a99ef3"}],"recentChangeFlags":null},{"id":"77a9ee32-ee69-4256-9fa4-d16b42ad7868","uri":"","name":"*.USCIS.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f5743cc5-cf01-4bf9-8ac3-21215826d7bd","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"77a9ee32-ee69-4256-9fa4-d16b42ad7868"}],"recentChangeFlags":null},{"id":"2417e56d-1bdf-4611-af64-d1a2ee9b6caa","uri":"","name":"*.USSS.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ae48fd1a-fb3c-4f30-b9b7-fc52282ab053","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2417e56d-1bdf-4611-af64-d1a2ee9b6caa"}],"recentChangeFlags":null},{"id":"9fc7cf8d-d7a0-4c6a-ae63-de95dafb06d0","uri":"","name":"*.TRUMPCARD.GOV","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"835f580a-0b0c-41c3-96e5-ea0c42db4239","sortOrder":40},"sortOrder":40,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9fc7cf8d-d7a0-4c6a-ae63-de95dafb06d0"}],"recentChangeFlags":null},{"id":"2a349fc4-f9e9-4f96-8ecc-20323ecbea90","uri":"https://trumpcard.gov","name":"trumpcard.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b836559d-7341-491c-b088-c6c2b014599e","sortOrder":41},"sortOrder":41,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2a349fc4-f9e9-4f96-8ecc-20323ecbea90"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis policy applies to any internet-accessible information system, application, or website owned, operated, or controlled by DHS, including any web or mobile applications hosted on those sites. Contractor information systems operated on behalf of DHS are not included within the scope of this policy.\u003c/p\u003e\n\n\u003cp\u003eAny subsequent Salesforce-related report within the same system and using the same technique would be considered a duplicate.\u003c/p\u003e\n\n\u003cp\u003eThis policy applies to the following systems and services:\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"7e9b3395-f86c-4c48-a419-b08dcf75b287","name":"Out of Scope","targets":[{"id":"12e08475-450e-4e43-a3d3-f22dffa68454","uri":"","name":"All third party sites and endpoints","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"93edb955-b580-4e40-a482-9ae3750834e4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"3513b617-9754-42a9-9fee-73115852ee19","code":"dhs-vdp","state":"in_progress","endsAt":null,"bountyId":"7157f025-b184-437e-bf8f-44074dcb5d8b","startsAt":"2021-07-29T13:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/b247/92a4/c0a60c02/bd46d087f733e7676a90e21cccaba5a0_dhslogo.JPG","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-07-29T13:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/dhs-vdp","changelogs":"/engagements/dhs-vdp/changelog","submissions":null,"announcements":"/engagements/dhs-vdp/announcements","hallOfFame":"/engagements/dhs-vdp/hall_of_fames","crowdstream":"/engagements/dhs-vdp/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/dhs-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=dhs-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/dhs-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/dhs-vdp/changelog","publishedAt":"2025-12-19T20:32:33.783Z","engagementChangelogUrl":"/engagements/dhs-vdp/changelog/8e83af01-4187-4573-a7ea-339b93ed6bc5","createUserFeedbacksUrl":"/engagements/dhs-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/dhs-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}