{"id":"4f54a257-1e9e-474e-b4f1-5e253c9d7e91","engagementId":"5fea50d9-5806-4ed9-872c-98ddd499f257","data":{"brief":{"id":"7f3e09be-ea0c-48bf-adc7-69bccbdf2079","name":"U.S. Fish and Wildlife Service ","tagline":"Vulnerability Disclosure Policy","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eIn the  U.S. Fish and Wildlife Service, we are committed to ensuring the security of the American public by protecting their information. As part of this, we recognize that public contributions can greatly enhance our ability to remediate security vulnerabilities before they can be exploited by an adversary. We encourage security researchers to report potential vulnerabilities in our systems so that we can address any associated security issues.\u003c/p\u003e\n\n\u003cp\u003eIn accordance with Department of Homeland Security Binding Operational Directive 20-01, we are issuing this Vulnerability Disclosure Policy to provide potential security researchers from the public with clear guidelines for conducting these vulnerability discovery activities. Our policy is drawn from the Department of the Interior (DOI) Vulnerability Disclosure Policy. It addresses what Service systems are within the scope of vulnerability reporting and provides instructions for submitting discovered vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eSo long as you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized. Our Cyber Security personnel will work with you to understand and resolve the issue quickly and the Service will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eWe would like to emphasize that once you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information (PII), financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose the data to anyone else.\u003c/p\u003e\n\n\u003cp\u003eFor reference, PII includes any information that permits the identity of an individual to be directly or indirectly inferred, including any information that is linked or linkable to an individual. This could include information like names, contact information, Social Security numbers, financial account numbers, date of birth, biometric identifiers (e.g., fingerprints, facial images), and medical or health information.\u003c/p\u003e\n\n\u003cp\u003eFor more information on our security research guidelines, including allowable testing methods, please review the \u003ca href=\"https://bugcrowd.com/doi-vdp\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDOI Vulnerability Disclosure Policy\u003c/a\u003e “Guidelines” section.\u003c/p\u003e\n\n\u003ch3\u003eProhibited Testing Methods\u003c/h3\u003e\n\n\u003cp\u003eThe following test methods are not allowed:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data\u003c/li\u003e\n\u003cli\u003ePhysical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing\u003c/li\u003e\n\u003cli\u003eFull red-team penetration testing that involves unauthorized access to our servers\u003c/li\u003e\n\u003cli\u003eFWS systems or services that are not expressly included within this section.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eQuestions\u003c/h2\u003e\n\n\u003cp\u003eQuestions about this policy can be sent to VulnerabilityDisclosures@fws.gov.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThe Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Platform (VDP Platform) gives agencies the option to use a centrally managed system to intake vulnerability information from and collaborate with the public to improve the security of their internet-accessible systems. CISA has a contract with EnDyna and Bugcrowd, private companies, to manage the platform used by the public to report vulnerability information; CISA exercises general oversight of the program.  CISA does not collect, maintain, use, or disseminate any Personally Identifiable Information (PII) provided to Bugcrowd for the purposes of creating a profile on the website or reporting a vulnerability to agencies other than CISA.  Participating agencies provide their own program vulnerability disclosure policy, setting out the agency’s parameters for vulnerability disclosures, including provisions for collection and use of submitted information. Any submissions of vulnerabilities pertaining to CISA’s own information systems would be governed by the DHS VDP brief.\u003c/p\u003e","safeHarborStatus":null,"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"979a75aa-8da5-43ef-b6d8-a800b674a1ec","name":"In Scope","targets":[{"id":"bb48fae9-38d8-479c-8588-518e16b94cd7","uri":"","name":"*.fws.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bfa6900e-3653-44f9-8036-1bc7f907ea76","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bb48fae9-38d8-479c-8588-518e16b94cd7"}],"recentChangeFlags":null},{"id":"b171e569-591b-4ab9-ae65-d058f4765d33","uri":"","name":"*.rivers.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5c8a4e16-5874-423f-9898-c0df4f0f4745","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b171e569-591b-4ab9-ae65-d058f4765d33"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThe following systems and services are currently under scope:\u003c/p\u003e\n\n\u003cp\u003eThis list will be updated over time as new systems and services are placed under the scope. No testing or research activities should be conducted on any FWS systems or services that are not expressly included within this section.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"5fea50d9-5806-4ed9-872c-98ddd499f257","code":"fws-vdp","state":"in_progress","endsAt":null,"bountyId":"507b4853-6130-4d36-adba-5ab46efdc044","startsAt":"2022-02-24T07:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/3f42/f49b/cabf125a/d5069384c6a4e39a75a9ff1a3cc1299a_SQUARE-US-FWS-logo.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-02-24T07:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fws-vdp","changelogs":"/engagements/fws-vdp/changelog","submissions":null,"announcements":"/engagements/fws-vdp/announcements","hallOfFame":"/engagements/fws-vdp/hall_of_fames","crowdstream":"/engagements/fws-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/fws-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fws-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fws-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/fws-vdp/changelog","publishedAt":"2023-01-27T17:39:30.552Z","engagementChangelogUrl":"/engagements/fws-vdp/changelog/4f54a257-1e9e-474e-b4f1-5e253c9d7e91","createUserFeedbacksUrl":"/engagements/fws-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/fws-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}