{"id":"4248ff0c-264f-4a90-910a-2d3d5d5bcb33","engagementId":"f7b4f124-18a5-4484-987e-3ee01515bab4","data":{"brief":{"id":"c1da5ae1-f60f-4452-b0f5-2d137a947913","name":"Orderly Network: Bug Bounty Program","tagline":"Next-Generation Trading Infrastructure,Decentralized Orderbook Protocol for DeFi builders","description":"\u003cp\u003eNo technology is perfect and Orderly Network believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications and API. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eThe final bounty will be the Base Bounty  +Special Bonus (if any) \u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003etype\u003c/th\u003e\n\u003cth\u003eCategory\u003c/th\u003e\n\u003cth\u003eMaximum Rewards\u003c/th\u003e\n\u003cth\u003eNotes\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eRemote Code Execution (RCE)\u003c/td\u003e\n\u003ctd\u003e$10,000\u003c/td\u003e\n\u003ctd\u003eThe ability to execute arbitrary system commands on a remote server with no circumstances beyond the attacker’s control will qualify for a maximum reward.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eServer Side Request Forgery (SSRF)\u003c/td\u003e\n\u003ctd\u003e$6000 – $9000\u003c/td\u003e\n\u003ctd\u003eThe ability to make arbitrary network requests within Orderly Network’s internal network and read sensitive data would qualify for a maximum reward. Factors that may limit severity include: Blind SSRF (unable read data or only certain file types, like images) and Limited to the type of requests that can be made (e.g. POST only).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eSQL Injection\u003c/td\u003e\n\u003ctd\u003e$6000 – $9000\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eSensitive File Access\u003c/td\u003e\n\u003ctd\u003e$6000 – $9000\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eAccount takeover\u003c/td\u003e\n\u003ctd\u003e$2000 – $4000\u003c/td\u003e\n\u003ctd\u003eThe maximum reward is reserved for account takeover vulnerabilities that require no user interaction.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eLogic flaw\u003c/td\u003e\n\u003ctd\u003e$2000 – $4000\u003c/td\u003e\n\u003ctd\u003eThis includes (non-exhaustive) ways to exploit the fact that the application does not behave as expected, such as: Changing/altering of parameters that results in unintended behavior (Eg: IDOR) or Bypassing paywall, approval process, business workflow within the application or Bypassing authentication mechanism.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eCross-Site Scripting (XSS)\u003c/td\u003e\n\u003ctd\u003e$1000 - $2000\u003c/td\u003e\n\u003ctd\u003eXSS vulnerabilities are limited to a base reward of $1,000. If you can access sensitive data, you may also be eligible for the PII bonus. If the XSS can be escalated to a more severe vulnerability, it will be evaluated under that category.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eCSRF\u003c/td\u003e\n\u003ctd\u003e$1000 - $2000\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003eOther valid vulnerabilities\u003c/td\u003e\n\u003ctd\u003e$200 - $1500\u003c/td\u003e\n\u003ctd\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eBonus rewards in addition to base bounties:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eBonus amount\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eSpecial Bonus\u003c/td\u003e\n\u003ctd\u003eUp to $5000\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch3\u003eReport Assessment and Bounty Calculations\u003c/h3\u003e\n\n\u003cp\u003e1) Base Bounty Maximum reward is based on the bounty table. The report is then evaluated based on maximum reward, CVSS and an evaluation of the business impact.\u003c/p\u003e\n\n\u003cp\u003e2) Other rewards: Special Bonus This category is for rewarding special contributions. This is entirely up to the Orderly Network Bug Bounty team’s discretion, but the goal is to reward reports we consider exceptional. Reports that qualify based on the below will have their bounty increased up to $5,000.\u003c/p\u003e\n\n\u003cp\u003eA few examples of things we will be looking for are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNovel and innovative approach and exploit \u003c/li\u003e\n\u003cli\u003eCreative chaining of exploits \u003c/li\u003e\n\u003cli\u003eEasy to understand report and good description root cause of issue\u003c/li\u003e\n\u003cli\u003eVulnerabilities that could undermine the safety of any user or validator's fund/fee\u003c/li\u003e\n\u003cli\u003eVulnerabilities related to key generation, encryption, decryption, signing and verification\u003c/li\u003e\n\u003cli\u003eRemote leaks of unencrypted private keys / mnemonic / key seed\u003c/li\u003e\n\u003cli\u003eVulnerabilities that could severely undermine trading or token economy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eExamples of issues that we are looking for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that can cause a loss of user funds/assets remotely\u003c/li\u003e\n\u003cli\u003eVulnerabilities that can cause exposure of private keys or mnemonic seed phrase remotely\u003c/li\u003e\n\u003cli\u003eVulnerabilities in chain-related implementations\u003c/li\u003e\n\u003cli\u003eDenial of service of the wallet app\u003c/li\u003e\n\u003cli\u003eRemote code execution\u003c/li\u003e\n\u003cli\u003eInsecure cryptographic implementation for sensitive functions such as wallet generation, transaction signing etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut-of-scope Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003eNon-Qualifying Vulnerabilities  in the Orderly Network\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTheoretical vulnerabilities without actual proof of concept\u003c/li\u003e\n\u003cli\u003eEmail verification deficiencies, expiration of password reset links, and password complexity policies\u003c/li\u003e\n\u003cli\u003eClickjacking/UI redressing with minimal security impact\u003c/li\u003e\n\u003cli\u003eEmail enumeration (E.g. the ability to identify emails via password reset)\u003c/li\u003e\n\u003cli\u003eInformation disclosure with minimal security impact (E.g. stack traces, path disclosure, directory listings, logs)\u003c/li\u003e\n\u003cli\u003eSelf-XSS\u003c/li\u003e\n\u003cli\u003eSpamming\u003c/li\u003e\n\u003cli\u003eUsability issues\u003c/li\u003e\n\u003cli\u003eVulnerabilities only exploitable on out-of-date browsers or platforms\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans, without exploitability demonstration\u003c/li\u003e\n\u003cli\u003eVulnerabilities related to autofill web forms\u003c/li\u003e\n\u003cli\u003eUse of known vulnerable libraries without actual proof of concept\u003c/li\u003e\n\u003cli\u003eLack of security flags in cookies\u003c/li\u003e\n\u003cli\u003eIssues related to unsafe SSL/TLS cipher suites or protocol version\u003c/li\u003e\n\u003cli\u003eContent spoofing\u003c/li\u003e\n\u003cli\u003eCache-control related issues\u003c/li\u003e\n\u003cli\u003eExposure of internal IP address or domains\u003c/li\u003e\n\u003cli\u003eMissing security headers that do not lead to direct exploitation\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require physical access to a user's device\u003c/li\u003e\n\u003cli\u003eNon-technical attacks, such as a physical attack, social engineering, phishing, etc.(E.g. HTTP Basic Authentication Phishing)\u003c/li\u003e\n\u003cli\u003eDNS takeover(Subdomain takeover)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Orderly Network} not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Orderly Network, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003eIn order to access the application you cannot be in one of the following countries: Cayman Islands, Belarus, Burma, Cote D'Ivoire (Ivory Coast), Cuba, United States of America, Crimea and Sevastopol, Democratic Republic of Congo, Iran, Iraq, Liberia, North Korea, Sudan, South Sudan, Syria, Zimbabwe, Republic of North Macedonia, Albania, Kosovo, Montenegro, Serbia, Bosnia and Herzegovina, China.\u003c/p\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003ePlease sign up using your @bugcrowdninja.com email\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny type of authentication or authorization issues\u003c/li\u003e\n\u003cli\u003eUser locking\n\n\u003cul\u003e\n\u003cli\u003eCan you lock another user out from their account\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0b60d3b8-b256-40f5-8a6e-b1d997433223","name":"██████████████","targets":[{"id":"ed382e52-06c7-49dc-8da3-e4da212c3ffc","uri":null,"name":"████████████████████████████","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2fcfb420-4910-45f8-b5fd-2c1b13b0c533","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"ed382e52-06c7-49dc-8da3-e4da212c3ffc"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"ed382e52-06c7-49dc-8da3-e4da212c3ffc"}],"recentChangeFlags":null},{"id":"e1516eaa-8c02-4a7a-bf0c-5a5265ade010","uri":null,"name":"████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5687db1d-3480-4860-ad49-213841ebdf28","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e1516eaa-8c02-4a7a-bf0c-5a5265ade010"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"e1516eaa-8c02-4a7a-bf0c-5a5265ade010"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e1516eaa-8c02-4a7a-bf0c-5a5265ade010"}],"recentChangeFlags":null},{"id":"cc158b56-4ad7-4bc4-b2d1-7da4e06ef827","uri":null,"name":"████████████████████████","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4fced501-1dd8-4c22-8aad-bdaceeca3619","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"cc158b56-4ad7-4bc4-b2d1-7da4e06ef827"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"cc158b56-4ad7-4bc4-b2d1-7da4e06ef827"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"d7faef49-5a8a-488f-b454-6f96f48bd72f","p1MaxCents":900000,"p1MinCents":600000,"p2MaxCents":400000,"p2MinCents":300000,"p3MaxCents":120000,"p3MinCents":60000,"p4MaxCents":60000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":1000000},"descriptionHtml":"████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":6000,"max":9000},"2":{"min":3000,"max":4000},"3":{"min":600,"max":1200},"4":{"min":200,"max":600},"5":{"min":null,"max":null},"programMax":10000},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f7b4f124-18a5-4484-987e-3ee01515bab4","code":"orderlynetwork-mbb-og","state":"in_progress_paused","endsAt":"2024-09-26T16:18:00Z","bountyId":"7659e4ab-1204-4817-a54b-a7d3ce17a42e","startsAt":"2023-11-09T00:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/f8b6/a0a9/0fd62e0f/bbe36577e542e6ed7cd075127c225fd1_2023-09-20_14.47.18.jpg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"The program will be moving to the other version listed in the announcements section.","lastTransitionAt":"2024-09-26T16:16:32.153Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/orderlynetwork-mbb-og","changelogs":"/engagements/orderlynetwork-mbb-og/changelog","submissions":null,"announcements":"/engagements/orderlynetwork-mbb-og/announcements","hallOfFame":"/engagements/orderlynetwork-mbb-og/hall_of_fames","crowdstream":"/engagements/orderlynetwork-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=orderlynetwork-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/orderlynetwork-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/orderlynetwork-mbb-og/changelog","publishedAt":"2024-09-26T16:17:34.993Z","engagementChangelogUrl":"/engagements/orderlynetwork-mbb-og/changelog/4248ff0c-264f-4a90-910a-2d3d5d5bcb33","createUserFeedbacksUrl":"/engagements/orderlynetwork-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/orderlynetwork-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}