{"id":"ca45da66-501a-492a-986f-9e34c130e1c5","engagementId":"cc3f2a39-e94f-432c-b5c9-d8cdf992b51d","data":{"brief":{"id":"ebd87a2b-bffc-4c9b-99e1-e2b9db7131c8","name":"HotDoc","tagline":"Easily book and manage all your appointments from one place.","description":"\u003cp\u003eHotDoc is Australia’s leading patient engagement platform, which is trusted by over 8,000 GPs. We help practices improve the depth of their relationships with patients and improve practice efficiency. We want to become the technology used by patients and healthcare providers to coordinate care and empower patients to manage their health.\u003c/p\u003e\n\n\u003cp\u003eHotDoc invites you to test and help secure our primary publicly facing assets - focusing on our web, and mobile applications. We appreciate your efforts and hard work in making the internet (and HotDoc) more secure, and look forward to working with the researcher community to create a meaningful and successful bug bounty program. Good luck and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"50214b57-2dde-40fd-ae5a-6680372523d4","targetsOverview":"\u003cp\u003e\u003cem\u003eAny domain/property of HotDoc not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e\u003cbr\u003e\n\u003cem\u003ePlease note that submissions found outside of the specified targets will be rewarded points only at this time.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eAccess \u0026amp; Program Rules\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eRequired headers\u003c/strong\u003e  - Bugcrowd researchers must add the header \"Bugcrowd: 38fd3272-b289-4e03-9a90-8adf34cb5d95\" to all requests, which will allow them to hit the \u003ca href=\"https://bugcrowd.hotdoc.com.au\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ebugcrowd.hotdoc.com.au\u003c/a\u003e domain**\u003c/p\u003e\n\n\u003cp\u003eThis bug bounty program has a dedicated domain for security researchers at \u003ca href=\"https://bugcrowd.hotdoc.com.au\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ebugcrowd.hotdoc.com.au\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eAll requests to this domain require a the header \"Bugcrowd: 38fd3272-b289-4e03-9a90-8adf34cb5d95\" to be set on all requests, or you will receive a \"418 - I'm a teapot\" response 🍵.\u003c/p\u003e\n\n\u003cp\u003eSee \u003cstrong\u003ethe \"Attaching the custom header\" section below\u003c/strong\u003e for more details on how to configure this header on all your pen testing requests if you're not sure how.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRate limits and scanning\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003ePlease be mindful when using scanning tools and test automation when testing to have sensible rate limits and to not leave the scanning unattended. If you have any questions about what this needs to be please contact Bugcrowd support. \u003c/p\u003e\n\n\u003ch1\u003eCredentials\u003c/h1\u003e\n\n\u003cp\u003eFor the purposes of this program, we have created two utilities allowing you to create credentials for both clinic users and patients.\u003cbr\u003e\nThese utilities are out of scope and are provided for convenience only. Please also note that they will bypass email, mobile phone number and strong password verification.\u003c/p\u003e\n\n\u003ch2\u003eClinic Credentials\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003eGo to \u003ca href=\"https://bugcrowd.hotdoc.com.au/clinic_users/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/clinic_users/new\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eEnter an email address\u003c/li\u003e\n\u003cli\u003eA demo clinic will be created for you, and some demo data will be seeded\u003c/li\u003e\n\u003cli\u003eYou should receive an email which will allow you to set your password\u003c/li\u003e\n\u003cli\u003eFollow the link, and choose a password\u003c/li\u003e\n\u003cli\u003eYou can now log into the Clinic Dashboard at \u003ca href=\"https://bugcrowd.hotdoc.com.au/dashboard\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/dashboard\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003ePatient Credentials\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003eGo to \u003ca href=\"https://bugcrowd.hotdoc.com.au/patients/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/patients/new\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eEnter an email address\u003c/li\u003e\n\u003cli\u003eEnter a password with confirmation (for the purposes of testing, we are not enforcing strong password requirements here)\u003c/li\u003e\n\u003cli\u003eA demo patient will be created\u003c/li\u003e\n\u003cli\u003eYou can now log into the patients portal at \u003ca href=\"https://bugcrowd.hotdoc.com.au/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003ePlease note:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe credential generation feature is out of scope, as it is visible for the Bug Bounty deployment only - in production, Clinic users are created by HotDoc employees\u003c/li\u003e\n\u003cli\u003eWhilst creating a few accounts for testing purposes is fine, please do not create more than a handful of accounts in a short amount of time (especially with an automated tool) as the demo data seeding process is quite intensive.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eTarget Info\u003c/h1\u003e\n\n\u003ch2\u003eHotDoc Patients\u003c/h2\u003e\n\n\u003cp\u003eThis functionality allows you to book appointments, search for medical centers\u003c/p\u003e\n\n\u003ch2\u003eHotDoc Clinic Dashboard\u003c/h2\u003e\n\n\u003cp\u003eThis functionality allows you to manage:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOnline Bookings\u003c/li\u003e\n\u003cli\u003ePatients\u003c/li\u003e\n\u003cli\u003eAppointment Reminders\u003c/li\u003e\n\u003cli\u003eScheduled Health Reminders (Recalls)\u003c/li\u003e\n\u003cli\u003eHealth Information Delivery\u003c/li\u003e\n\u003cli\u003eAppointment Check-In\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eOther info\u003c/h1\u003e\n\n\u003ch2\u003eRecalls\u003c/h2\u003e\n\n\u003cp\u003eInstead of being packaged with credentials, your short URL is now \u003ccode\u003ehttps://bugcrowd.hotdoc.com.au/short_urls/(the first 10 characters of your password)\u003c/code\u003e and verifying with last name: \u003ccode\u003eBugcrowd\u003c/code\u003e and date of birth: \u003ccode\u003e01/01/1970\u003c/code\u003e\u003c/p\u003e\n\n\u003ch2\u003eHotDoc API Routes/API Map\u003c/h2\u003e\n\n\u003cp\u003eWhile HotDoc itself doesn't have a public API, the resources section of this program has a resource detailing all of the API endpoints and actions. This could be helpful in finding areas to test without needing the UI.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eWe want to focus on anything that exposes user's identifiable sensitive data, has the capability to exfiltrate large amounts of data, or anything that would constitute a breach under Australian data laws. \u003ca href=\"https://www.oaic.gov.au/privacy-law/privacy-act/notifiable-data-breaches-scheme\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.oaic.gov.au/privacy-law/privacy-act/notifiable-data-breaches-scheme\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eForms\u003c/h2\u003e\n\n\u003cp\u003eThe Forms feature allows Clinics to create forms that they have patients fill out. To create a new form, visit this endpoint as a dashboard user: \u003ca href=\"https://bugcrowd.hotdoc.com.au/dashboard#/forms/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/dashboard#/forms/new\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eTo edit your form (or someone else's if you can), you can find the ID of the form (visible in the responses from the server) and visit \u003ccode\u003eforms/edit/$ID\u003c/code\u003e.\u003c/p\u003e\n\n\u003ch2\u003eMedical Centers Search\u003c/h2\u003e\n\n\u003cp\u003eWe have a new search feature for testing: \u003ca href=\"https://bugcrowd.hotdoc.com.au/medical-centres?exp=search:new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/medical-centres?exp=search:new\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003ePatient search on Dashboard\u003c/h2\u003e\n\n\u003cp\u003eA new patient search feature is available on Dashboard at \u003ca href=\"https://bugcrowd.hotdoc.com.au/dashboard#/patients/search\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.hotdoc.com.au/dashboard#/patients/search\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eHow does the patient search work?\u003c/h2\u003e\n\n\u003cp\u003eEndpoint: https://bugcrowd.hotdoc.com.au/api/dashboard/pms_patients?search=\u003cbr\u003e\nThe patient search functionality takes a patient's full name or partial name as the query parameter. It shows a list of matched patients and clinic users can manage the communication preference and view the patient activity of a selected patient. To assist your testing with this feature, we have seeded ten patients for each account.\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003e \u003c/th\u003e\n\u003cth\u003eFirst name\u003c/th\u003e\n\u003cth\u003eLast name\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e1\u003c/td\u003e\n\u003ctd\u003eNadia\u003c/td\u003e\n\u003ctd\u003eSchuster\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e2\u003c/td\u003e\n\u003ctd\u003eLouisa\u003c/td\u003e\n\u003ctd\u003eKulas\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e3\u003c/td\u003e\n\u003ctd\u003eFinn\u003c/td\u003e\n\u003ctd\u003eLeuschke\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e4\u003c/td\u003e\n\u003ctd\u003eMaeve\u003c/td\u003e\n\u003ctd\u003eCasper\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e5\u003c/td\u003e\n\u003ctd\u003eMarcelina\u003c/td\u003e\n\u003ctd\u003eZulauf\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e6\u003c/td\u003e\n\u003ctd\u003eNewton\u003c/td\u003e\n\u003ctd\u003eMcDermott\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e7\u003c/td\u003e\n\u003ctd\u003eFrieda\u003c/td\u003e\n\u003ctd\u003eWilkinson\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e8\u003c/td\u003e\n\u003ctd\u003eKieran\u003c/td\u003e\n\u003ctd\u003eGorczany\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e9\u003c/td\u003e\n\u003ctd\u003eAnnabelle\u003c/td\u003e\n\u003ctd\u003eCorwin\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e10\u003c/td\u003e\n\u003ctd\u003eIsom\u003c/td\u003e\n\u003ctd\u003eDickens\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch1\u003eAttaching the custom header\u003c/h1\u003e\n\n\u003cp\u003eAs mentioned above, all requests to the \u003ca href=\"https://bugcrowd.hotdoc.com.au\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ebugcrowd.hotdoc.com.au\u003c/a\u003e require the Bugcrowd header to be set with the correct value.\u003c/p\u003e\n\n\u003ch2\u003eExample\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e$ curl -I https://bugcrowd.hotdoc.com.au\nHTTP/2 418\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cp\u003eAbove: a GET request to the subdomain receives a 418 status code.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e$ curl -I -H \"Bugcrowd: 38fd3272-b289-4e03-9a90-8adf34cb5d95\" https://bugcrowd.hotdoc.com.au\nHTTP/2 200\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cp\u003eAbove: a GET request with the custom header receives a 200 OK status code.\u003c/p\u003e\n\n\u003cp\u003eOf course, using cURL only to pen test would be a nightmare, so, there are a few options to make this easier: Burp Suite \"match and replace\", a Burp Suite extension, or a Chrome extension.\u003c/p\u003e\n\n\u003ch2\u003eBurp Suite \"Match and Replace\"\u003c/h2\u003e\n\n\u003cp\u003eIf you are using Burp Suite as a proxy for your testing, it is possible to use the “Match and Replace” feature to automatically add the header to every request.\u003c/p\u003e\n\n\u003cp\u003eUnder the “Proxy” panel, in the “Options” tab, there are options for “Match and Replace”. If you click “Add”, you can specify a Request header match/replace rule, and leave the Match: condition blank, which will add a new header, rather than modify a header that is already present.\u003c/p\u003e\n\n\u003cp\u003eSet the value of the header you wish to send here, and it will add that header to every request that goes via the proxy.\u003c/p\u003e\n\n\u003ch2\u003eUsing a Burp Suite Extension\u003c/h2\u003e\n\n\u003cp\u003eThe \u003ca href=\"https://portswigger.net/bappstore/807907f5380c4cb38748ef4fc1d8cdbc\" title=\"https://portswigger.net/bappstore/807907f5380c4cb38748ef4fc1d8cdbc\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAdd Custom Header\u003c/a\u003e extension for Burp Suite will allow you to “Add or update custom HTTP headers from session handling rules”. This might be preferable to the “Match and Replace” option shown above.\u003c/p\u003e\n\n\u003ch2\u003eUsing a Chrome Extension\u003c/h2\u003e\n\n\u003cp\u003eIf you’re not using Burp Suite, another option is to use the Chrome Plugin \u003ca href=\"https://chrome.google.com/webstore/detail/modheader/idgpnmonknjnojddfkpgkljpfnnfcklj?hl=en\" title=\"https://chrome.google.com/webstore/detail/modheader/idgpnmonknjnojddfkpgkljpfnnfcklj?hl=en\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eModHeader\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eThis will allow you to browse via Chrome, and send the custom header through. You will probably want to configure it to either only send the header for the \u003ca href=\"http://bugcrowd.hotdoc.com.au/\" title=\"http://bugcrowd.hotdoc.com.au\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ebugcrowd.hotdoc.com.au\u003c/a\u003e subdomain - either through the configuration in the extension itself,  or by only enabling permissions for the given subdomain in the extension settings built into Chrome.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1de4aa4a-67a8-44e5-a999-55aed68458ee","name":"███████","targets":[{"id":"db7e43db-4947-4396-a530-2f81d8e82c6c","uri":null,"name":"█████████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a9968ee1-82d9-455a-a48d-553bf56f4f2c","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"db7e43db-4947-4396-a530-2f81d8e82c6c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"db7e43db-4947-4396-a530-2f81d8e82c6c"}],"recentChangeFlags":null},{"id":"12aec4e2-6bd5-4c7a-8c6b-aaa0e347397e","uri":null,"name":"██████████████████████████████████","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"dbf0d70b-7bef-46db-af64-c65d1bbe4c84","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"12aec4e2-6bd5-4c7a-8c6b-aaa0e347397e"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"12aec4e2-6bd5-4c7a-8c6b-aaa0e347397e"}],"recentChangeFlags":null},{"id":"b3753969-b76b-4ec7-884f-2732dd3ef895","uri":null,"name":"███████████████████████████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"046f8016-98ef-4389-9c56-7474de1e27bc","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"b3753969-b76b-4ec7-884f-2732dd3ef895"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b3753969-b76b-4ec7-884f-2732dd3ef895"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"561777a2-1e98-41e2-9462-47bd949df996","p1MaxCents":800000,"p1MinCents":400000,"p2MaxCents":300000,"p2MinCents":200000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":20000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":4000,"max":8000},"2":{"min":2000,"max":3000},"3":{"min":500,"max":1000},"4":{"min":50,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"68f08077-f776-450d-97a4-c80545662574","name":"████████████","targets":[{"id":"ff7810d7-49e7-4db8-86ef-db6eb94d5e8d","uri":null,"name":"███████████","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"53469fcb-92e5-41f2-a480-7e988d707185","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"ff7810d7-49e7-4db8-86ef-db6eb94d5e8d"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"ff7810d7-49e7-4db8-86ef-db6eb94d5e8d"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"ff7810d7-49e7-4db8-86ef-db6eb94d5e8d"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"ff7810d7-49e7-4db8-86ef-db6eb94d5e8d"}],"recentChangeFlags":null},{"id":"2adb9822-90e0-4f88-af9b-faea5a97b076","uri":null,"name":"███████","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d5419331-8249-47db-8ac2-cfe063892a3c","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"2adb9822-90e0-4f88-af9b-faea5a97b076"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"2adb9822-90e0-4f88-af9b-faea5a97b076"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"2adb9822-90e0-4f88-af9b-faea5a97b076"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"2adb9822-90e0-4f88-af9b-faea5a97b076"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"2adb9822-90e0-4f88-af9b-faea5a97b076"}],"recentChangeFlags":null},{"id":"9b6201e1-b731-4f46-a72f-b042796da103","uri":null,"name":"██████████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"37fcefd3-024f-4b10-a814-a095e9a39287","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"7b0811a5-2718-42f0-a3ae-ac0a6bc961f7","attachmentPath":"https://bugcrowd.com/engagements/hotdoc/attachments/7b0811a5-2718-42f0-a3ae-ac0a6bc961f7","name":"routes.txt","filename":"routes.txt","description":"The output of the `rails routes` task, which lists all endpoints and actions that the backend handles","icon":"fileOther","size":401275,"sizeLabel":"392 KB","uploadedAt":"7 Aug 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/hotdoc/attachments/7b0811a5-2718-42f0-a3ae-ac0a6bc961f7"}],"engagement":{"id":"cc3f2a39-e94f-432c-b5c9-d8cdf992b51d","code":"hotdoc","state":"in_progress_paused","endsAt":null,"bountyId":"97c0e1f6-fb8b-46c6-86ca-b2cf317ac11a","startsAt":"2019-01-17T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Healthcare","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/595d/b1d0/35d309a0/1fc8ef4ad47b2b52c0f19ad9e33f567e_69730caf737a78b1d9f91d9e75ac73a5_ZLdS9Bce_400x400.jpg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Effective immediately, we are pausing our engagements until further notice.\n\nWe apologize for the inconvenience and will let you know as soon as we have more information.\n\nIn the interim, Bugcrowd and HotDoc will be working together to continue triaging and validating all submissions that have come in to-date.\n\nWe appreciate your patience. If you have any questions, please [create a ticket with Bugcrowd Support](https://bugcrowd-support.freshdesk.com/support/tickets/new) to get them answered.\n","lastTransitionAt":"2025-12-05T07:15:56.935Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/hotdoc","changelogs":"/engagements/hotdoc/changelog","submissions":null,"announcements":"/engagements/hotdoc/announcements","hallOfFame":"/engagements/hotdoc/hall_of_fames","crowdstream":"/engagements/hotdoc/crowdstream"},"announcementsCount":36,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=hotdoc\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/hotdoc/engagement_subscribers","engagementChangelogsUrl":"/engagements/hotdoc/changelog","publishedAt":"2025-12-05T07:15:56.964Z","engagementChangelogUrl":"/engagements/hotdoc/changelog/ca45da66-501a-492a-986f-9e34c130e1c5","createUserFeedbacksUrl":"/engagements/hotdoc/feedbacks","engagementCrowdstreamUrl":"/engagements/hotdoc/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}