{"id":"d227fbed-0493-486e-a073-7dd275423337","engagementId":"134ce82b-edc1-48c0-9a65-1bc9625910e6","data":{"brief":{"id":"f7783c20-b0cd-4314-bfdc-ab0f662cd628","name":"oDesk ","tagline":"Get more done…","description":"\u003cp\u003eThrough our bounty program, we’ll provide rewards to eligible bug hunters who discover and discretely report verified oDesk site security bugs. We are excited about this program, but we also need you to understand that our decisions are final with respect to who gets a reward, what we reward, and if a reward is provided at all.\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003ch3\u003eCreate An Account - https://www.odesk.com/signup/user-type\u003c/h3\u003e\n\n\u003cp\u003eThere are 2 account registration types\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreate a Free Freelancer Account\u003c/li\u003e\n\u003cli\u003eCreate a Free Client Account\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote: Researchers that violate oDesks Terms of Service will forfeit their bounties.\u003c/p\u003e\n\n\u003ch3\u003eVulnerability Categories We Encourage\u003c/h3\u003e\n\n\u003cp\u003eWe are primarily interested in hearing about the following vulnerability categories:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross Site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eAuthentication related issues\u003c/li\u003e\n\u003cli\u003eAuthorization related issues\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003eRedirection Attacks\u003c/li\u003e\n\u003cli\u003eRemote Code Execution\u003c/li\u003e\n\u003cli\u003eParticularly clever vulnerabilities or unique issues that do not fall into explicit categories\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut of Scope Vulnerability Categories\u003c/h3\u003e\n\n\u003cp\u003eThe following vulnerability categories are considered out of scope and will not be eligible for credit on our researcher list:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of Service (DoS)\u003c/li\u003e\n\u003cli\u003eUser enumeration\u003c/li\u003e\n\u003cli\u003eBrute forcing\u003c/li\u003e\n\u003cli\u003eMixed Content\u003c/li\u003e\n\u003cli\u003eSecure flag not set on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eHTTPOnly flag not set on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eLogout Cross Site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eIssues only present in old browsers/old plugins/end-of-life software browsers\u003c/li\u003e\n\u003cli\u003eHTTP TRACE method enabled\u003c/li\u003e\n\u003cli\u003eVulnerability reports related to the reported version numbers of web servers, services, or frameworks\u003c/li\u003e\n\u003cli\u003eClickjacking on pages without authentication and/or sensitive state changes\u003c/li\u003e\n\u003cli\u003eVulnerability reports that would be more symptomatic of a social engineering or phishing attack and not an application vulnerability\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"19961c2e-6352-4f2d-98d5-b50f0549e5ae","name":"████████","targets":[{"id":"7e0b7a58-7a3e-4fc6-906c-d4c4e2072a58","uri":null,"name":"███████████","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4e2d4482-ebf6-453f-9530-8419bfe8fc9b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"134ce82b-edc1-48c0-9a65-1bc9625910e6","code":"odesk","state":"in_progress_paused","endsAt":null,"bountyId":"6448cf98-29cf-4527-8ed6-d675e14030d1","startsAt":"2014-10-15T16:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/0ee6/676f/e845a82c/74e6f155e10c06d74bd1d4bb09903daf_odesk22.jpg","logoBackgroundColor":"#64b034","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Paused until further notice","lastTransitionAt":"2015-07-10T06:35:37.274Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/odesk","changelogs":"/engagements/odesk/changelog","submissions":null,"announcements":"/engagements/odesk/announcements","hallOfFame":"/engagements/odesk/hall_of_fames","crowdstream":"/engagements/odesk/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=odesk\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/odesk/engagement_subscribers","engagementChangelogsUrl":"/engagements/odesk/changelog","publishedAt":"2020-02-13T00:30:15.122Z","engagementChangelogUrl":"/engagements/odesk/changelog/d227fbed-0493-486e-a073-7dd275423337","createUserFeedbacksUrl":"/engagements/odesk/feedbacks","engagementCrowdstreamUrl":"/engagements/odesk/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}