{"id":"473f8957-8a4e-4919-af9c-f860a75622c5","engagementId":"eaeb17d0-8fd5-4e2a-82e4-e7773609e065","data":{"brief":{"id":"925d1787-dde0-4efc-91eb-5d1824b58f87","name":"EchoStar Vulnerability Disclosure Engagement","tagline":"EchoStar, the fourth-largest wireless provider in America, has revolutionized rural TV. Satellite communications, internet services and is building America's first cloud-native 5G network.","description":"\u003cp\u003eEchoStar Corporation is a premier provider of technology, networking services, television entertainment and connectivity, offering consumer, enterprise, operator, and government solutions worldwide under its EchoStar®, Boost Mobile®, Sling TV ®, DISH® TV, Hughes®, HughesNet®, HughesON™ and JUPITER™ brands. \u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and EchoStar believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"78192436-6ce2-4bc8-a809-e4a20c182519","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed in the Scope section of the EchoStar Vulnerability Disclosure Policy below. Any targets or services not expressly addressed in the scope section of the EchoStar Vulnerability Disclosure Policy are excluded from scope and are not authorized for testing. If you aren't sure whether a system or endpoint is in scope or not, please file a Bugcrowd Support Ticket before starting your research.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eEchoStar Vulnerability Disclosure Policy\u003c/h3\u003e\n\n\u003cp\u003eEchoStar considers protecting the information of our customers, vendors, partners, employees, and organization a top priority that we take very seriously.  \u003c/p\u003e\n\n\u003cp\u003eWe recognize the value customers, security researchers, and security experts can provide to our organization toward addressing this responsibility.  We want all potential contributors to feel comfortable promptly reporting any vulnerabilities they may discover in our assets.  We welcome vulnerability disclosures in accordance with this policy and appreciate the opportunity to promptly remediate all such findings.\u003c/p\u003e\n\n\u003cp\u003eThis policy describes what systems and types of research are covered under this policy, how to send EchoStar vulnerability reports, and how long EchoStar asks security researchers to wait before disclosing discovered vulnerabilities outside of communications with BugCrowd and EchoStar.\u003c/p\u003e\n\n\u003ch4\u003eGuidelines\u003c/h4\u003e\n\n\u003cp\u003eEchoStar requires you:\u003c/p\u003e\n\n\u003cp\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.  Do not attempt to access accounts that do not belong to you. Do not attempt to access private information of any users. Do not attempt to modify or destroy data. Do not perform any type of denial-of-service attack.  Do not transmit malware, in any capacity.\u003c/p\u003e\n\n\u003cp\u003eOnly use exploits to the extent necessary to confirm a vulnerability. Do not use an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or use the exploit to \"pivot\" to other systems. Once you've established a vulnerability exists, or encountered any of the sensitive data outlined below, you must stop your test and notify us immediately.\u003c/p\u003e\n\n\u003cp\u003eClosely monitor any testing to ensure you are not compromising the integrity or availability of our assets; if you notice performance degradation of our assets, immediately suspend all testing and use of automated tools.\u003c/p\u003e\n\n\u003cp\u003eKeep confidential any information about discovered vulnerabilities for at least 90 calendar days after BugCrowd validation of your finding.\u003c/p\u003e\n\n\u003cp\u003eAre not a resident of any country under U.S. sanctions posted by the United States Treasury Department.\u003c/p\u003e\n\n\u003cp\u003eAre not an employee or contractor of EchoStar, its brands or subsidiaries and were not an employee or contractor within the past 6 months.\u003c/p\u003e\n\n\u003cp\u003eEnsure your research does not violate any U.S. law or laws of the country of origin where the work is conducted.\u003c/p\u003e\n\n\u003cp\u003ePlease remain patient throughout the submission, validation, and remediation process; once validated by BugCrowd, we will work to remediate your finding as a top priority.\u003c/p\u003e\n\n\u003ch4\u003eScope\u003c/h4\u003e\n\n\u003cp\u003eThis policy applies to the following systems:\u003c/p\u003e\n\n\u003cp\u003eAll domains owned by EchoStar and any brands or subsidiaries, including but not limited to the following:\u003c/p\u003e\n\n\u003cp\u003eEchoStar.com\u003c/p\u003e\n\n\u003cp\u003eHughes.com\u003c/p\u003e\n\n\u003cp\u003eHughesNet.com\u003c/p\u003e\n\n\u003cp\u003eDish.com\u003c/p\u003e\n\n\u003cp\u003eDishAnywhere.com\u003c/p\u003e\n\n\u003cp\u003eSling.com\u003c/p\u003e\n\n\u003cp\u003eBoostmobile.com\u003c/p\u003e\n\n\u003cp\u003eOnTechSmartServices.com\u003c/p\u003e\n\n\u003cp\u003eGenMobile.com\u003c/p\u003e\n\n\u003cp\u003eAll hardware products and associated software engineered, developed, and manufactured by EchoStar, any brand, or any subsidiary company.\u003c/p\u003e\n\n\u003cp\u003eAll applications published on Google Play or Apple App Store associated with EchoStar, any EchoStar brand, or any EchoStar subsidiary.\u003c/p\u003e\n\n\u003cp\u003eAny associated infrastructure vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eOther vulnerabilities in any other EchoStar-owned asset with demonstrated impact.\u003c/p\u003e\n\n\u003cp\u003eAny services not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in non-EchoStar systems from our vendors fall outside of this policy's scope and should be reported directly to the vendor according to their disclosure policy (if any).\u003c/p\u003e\n\n\u003cp\u003eIf you aren't sure whether a system or endpoint is in scope or not, contact us at echostar-vdp-pro@submit.bugcrowd.com before starting your research.\u003c/p\u003e\n\n\u003cp\u003eThe following test types are NOT authorized and are NOT in scope:\u003c/p\u003e\n\n\u003cp\u003eNetwork denial of service (DoS or DDoS) tests.\u003c/p\u003e\n\n\u003cp\u003ePhysical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), spam, or any other non-technical vulnerability testing.\u003c/p\u003e\n\n\u003cp\u003eSelf XSS (user defined payload).\u003c/p\u003e\n\n\u003cp\u003eUploading malware.\u003c/p\u003e\n\n\u003cp\u003eIf you encounter any of the below on our systems while testing within the scope of this policy, stop your test and notify us immediately:\u003c/p\u003e\n\n\u003cp\u003ePersonally Identifiable Information\u003c/p\u003e\n\n\u003cp\u003eCustomer Proprietary Network Information\u003c/p\u003e\n\n\u003cp\u003eFinancial Information (e.g. Credit Card or Bank Account Numbers)\u003c/p\u003e\n\n\u003cp\u003eProprietary Information or Trade Secrets of Companies (of any party)\u003c/p\u003e\n\n\u003ch4\u003eAuthorization\u003c/h4\u003e\n\n\u003cp\u003eIf you comply with this policy during your security research, we will consider your research to be authorized, will work with you to understand and resolve the issue quickly, and EchoStar will not initiate or recommend legal action related to your research.\u003c/p\u003e\n\n\u003cp\u003eNote: This policy does not grant permission to engage in any malicious activities. Unauthorized access, disruption of services, and any other malicious actions are strictly prohibited and may be subject to legal action.\u003c/p\u003e\n\n\u003ch4\u003eReporting a Vulnerability\u003c/h4\u003e\n\n\u003cp\u003eEchoStar accepts and discusses vulnerability reports via the BugCrowd submission form found below.  The form is the preferred and best means by which to submit your finding.  Use of the form helps ensure sufficient information is provided that allows us to understand and address your finding.\u003c/p\u003e\n\n\u003cp\u003eAlternatively, you may submit your finding via email to  echostar-vdp-pro@submit.bugcrowd.com following BugCrowd’s guidance for submissions.\u003c/p\u003e\n\n\u003cp\u003ePlease keep your vulnerability reports current by sending us any new information as it becomes available.\u003c/p\u003e\n\n\u003cp\u003eWe may share your vulnerability reports with US-CERT, as well as any affected vendors or open source projects.  However, please note vulnerabilities found in 3rd party software and systems (not owned by EchoStar) fall outside of this policy's scope and should instead be reported directly to that vendor according to their disclosure policy (if any).\u003c/p\u003e\n\n\u003ch4\u003eCoordinated Disclosure\u003c/h4\u003e\n\n\u003cp\u003eEchoStar is committed to remediating discovered vulnerabilities within 90 days or fewer following BugCrowd validation.\u003c/p\u003e\n\n\u003cp\u003eWe believe disclosure prior to remediation tends to increase risk rather than reduce it, and we ask you to please refrain from sharing reports with others while we work on our remediation efforts. If you believe there are others who should be informed of your report before remediation is completed, please let us know in your form submission or via echostar-vdp-pro@submit.bugcrowd.com.\u003c/p\u003e\n\n\u003cp\u003eShould you wish to post an advisory following our remediation, we would appreciate the opportunity to work with you to ensure sensitive information is redacted, so we ask that you please share the planned posting with us in advance via your form submission or via echostar-vdp-pro@submit.bugcrowd.com and allow us a reasonable amount of time to review and respond before self-disclosing.\u003c/p\u003e\n\n\u003ch4\u003ePolicy Revision\u003c/h4\u003e\n\n\u003cp\u003eEchoStar reserves the right to update and revise this policy as needed. Check this page regularly for the latest information.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eDue to the sensitive nature and risk security vulnerabilities may pose to our organization and its customers, vendors, and partners, we request you keep this information and our communications confidential, especially as we are working with you to confirm and address the issue.\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWe also request that you please:\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDirect your communications only at disclosures@dish.com.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not attempt to access accounts that do not belong to you.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not attempt to access private information of any users.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not attempt to modify or destroy data.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not perform any type of denial-of-service attack.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not transmit malware, in any capacity.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eClosely monitor any testing to ensure you are not compromising the integrity or availability of our assets; if you notice performance degradation of our assets, immediately suspend all testing and use of automated tools.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eComply with all applicable laws in connection with your testing actions.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eIf you are complying with our requests, we consider your vulnerability research to be:\u003c/h3\u003e\n\n\u003cp\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy.\u003c/p\u003e\n\n\u003cp\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls.\u003c/p\u003e\n\n\u003cp\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done in compliance with our requests.\u003c/p\u003e\n\n\u003cp\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/p\u003e\n\n\u003ch2\u003eWe ask that you refrain from reporting these issues:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhishing or Social Engineering techniques\u003c/li\u003e\n\u003cli\u003eForms missing CSRF tokens\u003c/li\u003e\n\u003cli\u003eLogout CSRF\u003c/li\u003e\n\u003cli\u003eAll Sender Policy Framework suggestions\u003c/li\u003e\n\u003cli\u003eDisclosure of public or known directories\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users who are using outdated or unpatched browsers and platforms\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003eWe don’t want to limit scope to a primary target.  However, the company is most excited about the future of our mobile network, devices, and offerings.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eN/A\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b8d7169b-987b-4198-b991-a954dcc76022","name":"In Scope","targets":[{"id":"6cdaf2be-0c7a-4f13-8fc3-7e9d14b66987","uri":"https://dish.com/","name":"*.dish.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"793481b1-d388-4fbd-bb98-53c8997e94e0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6cdaf2be-0c7a-4f13-8fc3-7e9d14b66987"}],"recentChangeFlags":null},{"id":"9fb15c32-ac91-4ed4-989a-0821f932f2f0","uri":"https://my.dish.com","name":"*.my.dish.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b1792841-fb7e-4a5b-9309-881b7a4b56fd","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9fb15c32-ac91-4ed4-989a-0821f932f2f0"}],"recentChangeFlags":null},{"id":"cc5acf5b-dc54-41eb-9ef1-2481e3a66d1e","uri":"https://dishanywhere.com","name":"*.dishanywhere.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"35f31085-480f-4bc8-8441-af609e07f210","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cc5acf5b-dc54-41eb-9ef1-2481e3a66d1e"}],"recentChangeFlags":null},{"id":"a1bfee17-997c-4dfd-b4fc-efe5e2b255c2","uri":"https://sling.com","name":"*.sling.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"eebb8c56-a980-4240-99a9-5e5a89ff1498","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a1bfee17-997c-4dfd-b4fc-efe5e2b255c2"}],"recentChangeFlags":null},{"id":"e01d7a93-d376-409c-94f0-87062583339a","uri":"https://ontechsmartservices.com","name":"*.ontechsmartservices.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"df7f53b6-feff-4d0b-be95-3ece8c2dbf82","sortOrder":4},"sortOrder":4,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e01d7a93-d376-409c-94f0-87062583339a"}],"recentChangeFlags":null},{"id":"6cbc05f6-07c4-4e8d-8c82-2dcd570433d9","uri":"https://boostmobile.com","name":"*.boostmobile.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c6b76d16-c21b-4918-8fac-00cb7555fcc5","sortOrder":5},"sortOrder":5,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6cbc05f6-07c4-4e8d-8c82-2dcd570433d9"}],"recentChangeFlags":null},{"id":"cb7ccc70-1d97-49f5-a522-26b8f74471c1","uri":"https://echostar.com","name":"*.echostar.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1b961efc-fe65-4a13-8bb6-77a861a9522d","sortOrder":6},"sortOrder":6,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cb7ccc70-1d97-49f5-a522-26b8f74471c1"}],"recentChangeFlags":null},{"id":"89ad4f94-adab-45e5-bef7-e8a5696778ce","uri":"https://hughesnet.com","name":"*.hughesnet.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"73dae843-0956-4eb2-ab0a-63a21ddbb4c6","sortOrder":7},"sortOrder":7,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"89ad4f94-adab-45e5-bef7-e8a5696778ce"}],"recentChangeFlags":null},{"id":"0bf05a41-68c8-46c8-bf0c-64e2d1935652","uri":"https://hughes.com","name":"*.hughes.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4acd890c-f5dc-45d7-9d6e-594146230482","sortOrder":8},"sortOrder":8,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0bf05a41-68c8-46c8-bf0c-64e2d1935652"}],"recentChangeFlags":null},{"id":"2ec42089-b622-423a-bb69-0db14916bdbe","uri":"https://apps.apple.com/us/app/dish-anywhere/id327125649","name":"Dish Anywhere iOS","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a3217521-03d2-4e46-b641-1da4678e1b5c","sortOrder":9},"sortOrder":9,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"2ec42089-b622-423a-bb69-0db14916bdbe"}],"recentChangeFlags":null},{"id":"56c89be0-730b-4bf2-a406-fa266a245c4f","uri":"https://play.google.com/store/apps/details?id=com.sm.SlingGuide.Dish","name":"Dish Anywhere Android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3d3ff449-4fc5-4f75-83d4-bcac4443c42e","sortOrder":10},"sortOrder":10,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"56c89be0-730b-4bf2-a406-fa266a245c4f"}],"recentChangeFlags":null},{"id":"bd28aeab-22db-4cfd-846c-8067c3d177ec","uri":"https://apps.apple.com/us/app/mydish-account/id1123102087","name":"MyDISH iOS","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"36480bdd-bf62-43da-a440-6b19d83fb0ae","sortOrder":11},"sortOrder":11,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"bd28aeab-22db-4cfd-846c-8067c3d177ec"}],"recentChangeFlags":null},{"id":"60d25d5c-9f6f-4cb2-b04b-14f736006819","uri":"https://play.google.com/store/apps/details?id=com.dish.mydish","name":"MyDISH Android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c3c3cc85-2b88-44f7-adeb-aa068a4a1236","sortOrder":12},"sortOrder":12,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"60d25d5c-9f6f-4cb2-b04b-14f736006819"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"eaeb17d0-8fd5-4e2a-82e4-e7773609e065","code":"dish-network-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"cc2457d4-9e78-4361-a74d-45cebc312a83","startsAt":"2024-11-12T17:30:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Utilities","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/50a7/a3ae/886ce8be/42cdfcf8209adbcc5697cac1a6934bbd_dish_network_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-11-12T18:00:00.544Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/dish-network-vdp-pro","changelogs":"/engagements/dish-network-vdp-pro/changelog","submissions":null,"announcements":"/engagements/dish-network-vdp-pro/announcements","hallOfFame":"/engagements/dish-network-vdp-pro/hall_of_fames","crowdstream":"/engagements/dish-network-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/dish-network-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=dish-network-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/dish-network-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/dish-network-vdp-pro/changelog","publishedAt":"2025-10-14T16:15:16.453Z","engagementChangelogUrl":"/engagements/dish-network-vdp-pro/changelog/473f8957-8a4e-4919-af9c-f860a75622c5","createUserFeedbacksUrl":"/engagements/dish-network-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/dish-network-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}