{"id":"32d7db64-022c-4996-b26b-91e66b1a4cc2","engagementId":"1f1ee80a-10d5-453d-bf10-65674ae0b4e7","data":{"brief":{"id":"227039c6-008d-4af5-ac4d-ec86e941f869","name":"RMIT University Vulnerability Disclosure Program","tagline":"RMIT is a global university of technology, design and enterprise. Please submit your findings to this program!","description":"\u003cp\u003eRMIT University takes the protection of its information, systems, and networks very seriously. We are implementing this Vulnerability Disclosure Program with the intent of removing or mitigating the potential impact(s) of security vulnerabilities that may exist on our systems or networks. We value the unique opportunity that this Program affords in engaging with the broader security research community to strengthen the security of our systems and networks.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Information:\u003c/h2\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003eTargets are public facing and have open access\u003c/p\u003e\n\n\u003ch3\u003eIn-scope\u003c/h3\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of RMIT not listed in the targets section is out of scope. This includes any/all subdomains not listed in the targets section. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to RMIT, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003cp\u003eRMIT uses third-party providers and services which may be hosted on subdomains of rmit.edu.au and rmit.edu.vn. These are all considered Out-of-Scope for this program even if they are not specifically mentioned in this Program Brief. RMIT does not and cannot authorise testing for vulnerabilities against systems or networks that do not belong to us. RMIT leaves it up to the individual security researcher’s discretion whether to report any issues identified within these services to the relevant third-party. However, if you believe an issue with one of our third-party service providers is the result of RMIT’s misconfiguration or insecure usage of that service (or you've reported an issue affecting many customers of the service that you believe RMIT can temporarily mitigate without stopping usage of the service while a fix is implemented upstream), we would greatly appreciate it if you reported these issues to us.\u003c/p\u003e\n\n\u003ch3\u003eRules of Engagement\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll submissions should be from your @bugcrowdninja.com email address.\u003c/li\u003e\n\u003cli\u003eUse your best efforts to avoid privacy violations, destruction of data, and interruption or degradation of any RMIT services, systems, or networks.\u003c/li\u003e\n\u003cli\u003eDo not conduct non-technical attacks such as social engineering, phishing, or unauthorised access to RMIT systems, networks, or infrastructure.\u003c/li\u003e\n\u003cli\u003eDo not modify any data or information\u003c/li\u003e\n\u003cli\u003eDo not in any way attack our customers or end users or use stolen/breached user credentials.\u003c/li\u003e\n\u003cli\u003eThe use of personal credentials, your own or discovered, for testing purposes is strictly prohibited. This program is set up as an unauthenticated program. If you have any questions regarding this matter, please contact support@bugcrowd.com.\u003c/li\u003e\n\u003cli\u003eResearchers will not pursue post-exploitation unless explicitly approved by RMIT.3\u003c/li\u003e\n\u003cli\u003eThe use of automated scanning tools is prohibited. \u003c/li\u003e\n\u003cli\u003eRecursive DNS enumeration should be kept to a minimum. \u003c/li\u003e\n\u003cli\u003eRMIT will not accept generic vulnerability scan results without working proof of exploit or a clear path to exploitation of a vulnerability.\u003c/li\u003e\n\u003cli\u003eTools that may result in a Denial of Service (DoS) are prohibited.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"f2d64fa8-5daf-49ef-8de8-edc7da2dfb4a","targetsOverview":"\u003cp\u003eAll researchers who sign up for testing are required to use their Bugcrowd email address. Please ensure you provide the BugURL field when making a submission\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eSecurity Header Requirement:\u003c/h3\u003e\n\n\u003cp\u003eTo prevent being throttled or blacklisted for testing on our targets, we do require the use of the following security header: bugcrowd_hacker_rmit\u0026lt;username\u0026gt;\u003c/p\u003e\n\n\u003ch3\u003eOut-of-Scope\u003c/h3\u003e\n\n\u003cp\u003eAny external-hosted environment that does not resolve to RMIT University’s DNS or IP address Ranges. Please be sure to check domain records and IP address registrations to confirm RMIT University ownership; do not test systems or targets not owned or controlled by RMIT University.\u003c/p\u003e\n\n\u003cp\u003eOut-of-Scope vulnerabilities include, but are not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf XSS\u003c/li\u003e\n\u003cli\u003eOut-of-date software (without an exploitable PoC)\u003c/li\u003e\n\u003cli\u003eAutomated Scans report (without an exploitable PoC.) For example, submitting known vulnerable versions Apache or PHP with no reproducible steps to prove an actual exploit are OOS.\u003c/li\u003e\n\u003cli\u003eContent Spoofing Vulnerabilities\u003c/li\u003e\n\u003cli\u003eDNS configuration related issues\u003c/li\u003e\n\u003cli\u003eHost Header Injection (without providing an exploitable scenario)\u003c/li\u003e\n\u003cli\u003eHTTP Trace method is enabled\u003c/li\u003e\n\u003cli\u003eIssues present only in older versions of browsers, plugins, or any other software\u003c/li\u003e\n\u003cli\u003eLow Impact CSRF issues, including but not limited to login and Logout CSRF\u003c/li\u003e\n\u003cli\u003eLow Severity Clickjacking Vulnerabilities\u003c/li\u003e\n\u003cli\u003eMissing Rate Limiting Protections (unless corresponding to authentication flow)\u003c/li\u003e\n\u003cli\u003eMissing SPF/DKIM/DMARC policies\u003c/li\u003e\n\u003cli\u003eMissing Security Headers and Cookie Flags, which can’t be exploited by themselves (for example Strict-Transport-Security, HTTPOnly)\u003c/li\u003e\n\u003cli\u003eServer Configuration related issues that are not exploitable\u003c/li\u003e\n\u003cli\u003eSocial engineering and phishing attacks\u003c/li\u003e\n\u003cli\u003eSpam e-mail (missing rate limiting protections)\u003c/li\u003e\n\u003cli\u003eSSL vulnerabilities related to configuration, version, weak ciphers (without a working exploit)\u003c/li\u003e\n\u003cli\u003eUse of a vulnerable 3rd party library/code snippet (without providing an exploitable scenario)\u003c/li\u003e\n\u003cli\u003eInfo.php (without providing an exploitable scenario)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eConfidentiality\u003c/h3\u003e\n\n\u003cp\u003eYou must treat all information or data about or on our systems, staff or users that comes into your possession or that you otherwise become aware of, which is not publicly available, as strictly confidential, and not share or otherwise use it for any purpose other than emailing it to us as a submission as described above. You are expected, as always, to comply at all times with all applicable laws and with the Bugcrowd Standard Disclosure Terms - \u003ca href=\"https://www.bugcrowd.com/resources/essentials/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eStandard Disclosure Terms | Bugcrowd\u003c/a\u003e.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"36351c43-182b-4c93-bd6e-1db1c12437f8","name":"In Scope","targets":[{"id":"2a3ff6e6-abd4-48ac-8964-81bb5e299a7a","uri":"","name":"*.rmit.edu.au","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9e3f5d6a-3ab0-42f8-a1bd-2de29e098c80","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2a3ff6e6-abd4-48ac-8964-81bb5e299a7a"}],"recentChangeFlags":null},{"id":"f9ba1409-134e-49b2-a364-fdd98be21060","uri":"","name":"*.rmit.edu.vn","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f67aafcf-d319-41ee-b541-bc5de27c425b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f9ba1409-134e-49b2-a364-fdd98be21060"}],"recentChangeFlags":null},{"id":"d8f56600-7a24-43b2-a695-3937f3c3d01f","uri":"","name":"*.Rmittraining.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"02809509-12ed-4009-9706-d1b05ef4c728","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d8f56600-7a24-43b2-a695-3937f3c3d01f"}],"recentChangeFlags":null},{"id":"0ea5136a-d64a-481b-96a2-758b3db6b4ac","uri":"","name":"Australia IP Ranges: 131.170.0.0/16 and 144.205.0.0/16","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"19c34676-00c5-4a45-ae74-bf6cfbc26cc4","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"0ea5136a-d64a-481b-96a2-758b3db6b4ac"}],"recentChangeFlags":null},{"id":"0c0218bd-45e5-40de-bf6a-5f89329794c2","uri":"","name":"Vietnam IP Ranges: 103.253.88.0/22 and 103.144.84.0/23","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0b866aac-cbb0-4186-96f9-93bb9452bf55","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"0c0218bd-45e5-40de-bf6a-5f89329794c2"}],"recentChangeFlags":null},{"id":"dac9ce6b-1f03-40b5-ab63-d18bf57898d5","uri":"","name":"203.17.179.0/24","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"56398805-9f5b-42a4-a2db-9087ca9d707b","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"dac9ce6b-1f03-40b5-ab63-d18bf57898d5"}],"recentChangeFlags":null},{"id":"9db67cf3-6fb6-43b8-afb3-a848c4fe7a62","uri":"","name":"ezproxy.rmit.edu.au","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0b2dfbd2-8b1b-4ed0-958d-3407431c38b8","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eNote: Any external-hosted environment that does not resolve to RMIT University’s DNS or IP address Ranges is out of scope. Please be sure to check domain records and IP address registrations to confirm RMIT University ownership; do not test systems or targets not owned or controlled by RMIT University.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"6bd66d71-3d8c-4ae7-b488-19ba6b372f61","name":"Out of scope ","targets":[{"id":"735956b1-93c4-403f-9b9b-f8bf47e722f3","uri":"","name":"*.ezproxy.rmit.edu.au ","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"865d01bf-5cb4-442c-b9e6-8daa7a87152c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"1f1ee80a-10d5-453d-bf10-65674ae0b4e7","code":"rmit-university-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"5710f79f-5795-4f2e-97e7-b0680827fbc5","startsAt":"2022-11-08T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Education","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/5600/6e2d/91bc9c0b/12e7afaabae1c3db8fba705902ca8694_1653619090353.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-11-08T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/rmit-university-vdp-pro","changelogs":"/engagements/rmit-university-vdp-pro/changelog","submissions":null,"announcements":"/engagements/rmit-university-vdp-pro/announcements","hallOfFame":"/engagements/rmit-university-vdp-pro/hall_of_fames","crowdstream":"/engagements/rmit-university-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/rmit-university-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=rmit-university-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/rmit-university-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/rmit-university-vdp-pro/changelog","publishedAt":"2025-12-12T04:46:35.538Z","engagementChangelogUrl":"/engagements/rmit-university-vdp-pro/changelog/32d7db64-022c-4996-b26b-91e66b1a4cc2","createUserFeedbacksUrl":"/engagements/rmit-university-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/rmit-university-vdp-pro/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}