{"id":"a0c0b96f-e254-445f-96b1-136f5c889199","engagementId":"06f02a2d-7d64-4b31-b4ab-f4bd78a677cf","data":{"brief":{"id":"83dc83bc-ba8f-4311-8d96-19b37b736090","name":"Monash University Vulnerability Disclosure Program","tagline":"Monash University Vulnerability Disclosure Program (VDP) ","description":"\u003cp\u003eMonash University is committed to protecting the confidentiality, integrity and availability of its information and digital platforms.  Our Vulnerability Disclosure Program is designed to minimise the impact of potential security vulnerabilities. At Monash, we value and support the work undertaken by the security research community and appreciate it when researchers take the time to report potential security vulnerabilities to us.\u003c/p\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"f2d64fa8-5daf-49ef-8de8-edc7da2dfb4a","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. _Any domain/property of Monash University not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e  \u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIF you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to Monash University AND you \u003cstrong\u003eprovide a valid proof of concept (POC) to exploit the identified bug\u003c/strong\u003e, it may be reported to this program, and is appreciated.  These out-of-scope submissions will be evaluated on a case by case basis and will either be marked as ‘not applicable’ or be awarded points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll email addresses belonging to researchers should be your @bugcrowdninja.com.\u003c/li\u003e\n\u003cli\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services.\u003c/li\u003e\n\u003cli\u003eDo not modify data that does not belong to you.\u003c/li\u003e\n\u003cli\u003eYou’ll be testing production systems, Please be reasonable with the use of automated tools.\u003c/li\u003e\n\u003cli\u003eTools that may result in a Denial Of Service (DoS) are prohibited. \u003c/li\u003e\n\u003cli\u003ePlease be sure to check domain records to confirm Monash University ownership; avoid testing of assets not owned and controlled by Monash University.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Information\u003c/h2\u003e\n\n\u003cp\u003eThis program covers all Monash University-owned applications, services, and properties, including any browser UI, web service, or mobile app for each product. \u003c/p\u003e\n\n\u003cp\u003eThe following IP CIDR Range is in scope: 130.194.0.0/19 (IP Range \u003cstrong\u003e130.194.0.0 - 130.194.31.255\u003c/strong\u003e)\u003cbr\u003e\n59.191.192.0/24 (IP Range  \u003cstrong\u003e59.191.192.1 - 59.191.192.254\u003c/strong\u003e)\u003c/p\u003e\n\n\u003cp\u003eSome examples include:\u003c/p\u003e\n\n\u003cp\u003eMonash University web sites\u003cbr\u003e\nMonash University mobile apps\u003cbr\u003e\nMonash University BMS environments \u003c/p\u003e\n\n\u003cp\u003eIdentity systems:\u003c/p\u003e\n\n\u003cp\u003ehttps://identity.idmqat.monash.edu/\u003cbr\u003e\nhttps://identity.idmqat.monash.edu/\u003cbr\u003e\nhttps://identity.idmqat.monash.edu/password-change\u003cbr\u003e\nhttps://identity.idmqat.monash.edu/sspr\u003cbr\u003e\nhttps://identity.idmqat.monash.edu/mfa-reset  \u003c/p\u003e\n\n\u003cp\u003eYou are encouraged to report on any security findings\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eAccess:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTargets are public facing and have open access\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eOut-of-Scope\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eOut of scope vulnerabilities include but are not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf XSS\u003c/li\u003e\n\u003cli\u003eOut-of-date software (without an exploitable PoC)\u003c/li\u003e\n\u003cli\u003eAutomated Scans report (without an exploitable PoC.)  For example, submitting known vulnerable versions Apache or PHP with no reproducible POC steps to prove an actual exploit are OOS.\u003c/li\u003e\n\u003cli\u003eContent Spoofing Vulnerabilities\u003c/li\u003e\n\u003cli\u003eDNS configuration related issues\u003c/li\u003e\n\u003cli\u003eHost Header Injection (without providing an exploitable scenario)\u003c/li\u003e\n\u003cli\u003eHTTP Trace method is enabled\u003c/li\u003e\n\u003cli\u003eIssues present only in older versions of browsers, plugins or any other software\u003c/li\u003e\n\u003cli\u003eLow Impact CSRF issues, including but not limited to login and Logout CSRF\u003c/li\u003e\n\u003cli\u003eLow Severity Clickjacking Vulnerabilities\u003c/li\u003e\n\u003cli\u003eMissing Rate Limiting Protections (unless corresponding to authentication flow)\u003c/li\u003e\n\u003cli\u003eMissing SPF/DKIM/DMARC policies\u003c/li\u003e\n\u003cli\u003eMissing Security Headers and Cookie Flags, which cant be exploited by themselves ( for example Strict-Transport-Security, HTTPOnly)\u003c/li\u003e\n\u003cli\u003eServer Configuration related issues that are not exploitable\u003c/li\u003e\n\u003cli\u003eSocial engineering and phishing attacks\u003c/li\u003e\n\u003cli\u003eSpam e-mail (missing rate limiting protections)\u003c/li\u003e\n\u003cli\u003eSSL vulnerabilities related to configuration, version, weak ciphers (without a working exploit)\u003c/li\u003e\n\u003cli\u003eUse of a vulnerable 3rd party library/code snippet (without providing an exploitable scenario)\u003c/li\u003e\n\u003cli\u003eInfo.php (without providing an exploitable scenario)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"906a5634-b40b-4ff2-b4f6-0fb921df465a","name":"In Scope ","targets":[{"id":"31046e84-de35-4ed7-8cee-750e4552168d","uri":"","name":"*.monash.edu","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2358c681-3279-44ef-91f8-581bbec8a6f3","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"31046e84-de35-4ed7-8cee-750e4552168d"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"31046e84-de35-4ed7-8cee-750e4552168d"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"9705f57e-4cab-4f51-b72b-725404a280de","name":"Monash eResearch Center","targets":[{"id":"a0c50860-fc85-4388-a641-dba40acbc1b1","uri":"","name":"*.erc.monash.edu","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3bb5857d-62ed-43cd-96d2-c68d1aff6a96","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"acdd43c8-ed57-4c99-bdcb-c48e73ef43a6","name":"Monash University Malaysia","targets":[{"id":"ace11a37-4d6e-4448-9ecb-cce6a0d1c1c9","uri":"https://*.monash.edu.my","name":"*.monash.edu.my","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"056fd2d6-9402-4628-8cb1-bea87f017d76","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"ace11a37-4d6e-4448-9ecb-cce6a0d1c1c9"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ace11a37-4d6e-4448-9ecb-cce6a0d1c1c9"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"315e250c-80d8-4764-8155-04cb5ad667da","name":"Monash Collage","targets":[{"id":"2b02912c-ed49-494b-89ee-af52a5f9c4cb","uri":"http://*.mcpl.edu.au","name":"*.mcpl.edu.au","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"75a3e688-5fc1-49f3-93c0-7f81fd41661f","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"2b02912c-ed49-494b-89ee-af52a5f9c4cb"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2b02912c-ed49-494b-89ee-af52a5f9c4cb"}],"recentChangeFlags":null},{"id":"f7e55c7d-6818-4a5c-ab7c-33c00ee91277","uri":"http://*.monashcollege.edu.au","name":"*.monashcollege.edu.au","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"25ef6774-5a11-43a8-9122-8f1e6d0ae6ec","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"f7e55c7d-6818-4a5c-ab7c-33c00ee91277"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f7e55c7d-6818-4a5c-ab7c-33c00ee91277"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"06f02a2d-7d64-4b31-b4ab-f4bd78a677cf","code":"monash-esf","state":"in_progress","endsAt":null,"bountyId":"0d7ae3b1-440e-49b8-b9bf-add3eb81c1d4","startsAt":"2020-06-23T11:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Education","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2ed0/d883/7d4017b2/7bcb5f32f98a914c8ace8590084f981d_Monash_logo.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-06-23T11:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/monash-esf","changelogs":"/engagements/monash-esf/changelog","submissions":null,"announcements":"/engagements/monash-esf/announcements","hallOfFame":"/engagements/monash-esf/hall_of_fames","crowdstream":"/engagements/monash-esf/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/monash-esf/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=monash-esf\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/monash-esf/engagement_subscribers","engagementChangelogsUrl":"/engagements/monash-esf/changelog","publishedAt":"2026-01-20T00:39:37.422Z","engagementChangelogUrl":"/engagements/monash-esf/changelog/a0c0b96f-e254-445f-96b1-136f5c889199","createUserFeedbacksUrl":"/engagements/monash-esf/feedbacks","engagementCrowdstreamUrl":"/engagements/monash-esf/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}