{"id":"0083959e-e0b6-4a7d-aee3-40cb5fa66999","engagementId":"53889660-1956-463e-996f-1c426f52c2a7","data":{"brief":{"id":"7d9e754b-146b-410a-b9b1-15663227951f","name":"RSAC Vulnerability Disclosure Engagement ","tagline":"RSAC is a global event for the cybersecurity community, bringing experts, unbiased content, and ideas to discuss current and future cybersecurity concerns.","description":"\u003cp\u003eAs the cybersecurity industry’s convening authority, RSAC brings together diverse minds to exchange perspectives, knowledge, and ideas. RSAC provides the world’s leading platform for uniting and advancing the cybersecurity community to create a safer society. RSAC is at the cutting edge of cybersecurity innovation and education. The company’s flagship event, RSAC™ Conference, is the largest and most influential global gathering in cybersecurity. RSAC gives cybersecurity professionals a platform to connect and grow.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and RSAC believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of RSA Conference not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to RSA Conference, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must contain a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll target within scope are publicly accessible from the internet\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003e🚨Community Platform Testing\u003c/h2\u003e\n\n\u003cp\u003eWhen testing features that involve posting or interacting within groups on the RSAC community platform, researchers must use the RSAC Vulnerability Disclosure Program group exclusively.\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://portal.onersac.com/link/share/groups/!kCoJFalCeYlCvjXVKD:415.onersac.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick here to access the RSAC VDP Testing Group\u003c/a\u003e\u003c/p\u003e\n\n\u003ch3\u003eRequired:\u003c/h3\u003e\n\n\u003cp\u003eAll community testing activities must be conducted within the designated VDP group\u003cbr\u003e\nOperate within defined scope boundaries at all times\u003c/p\u003e\n\n\u003ch3\u003eProhibited:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003ePublishing raw exploit code or weaponized tools\u003c/li\u003e\n\u003cli\u003eSharing unredacted sensitive data, credentials, or PII\u003c/li\u003e\n\u003cli\u003eConducting unauthorized scans or assessments\u003c/li\u003e\n\u003cli\u003eTesting against out-of-scope systems or networks\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication \u0026amp; Access Control\n\n\u003cul\u003e\n\u003cli\u003eFocus on secure access mechanisms, specifically around our Azure AD B2C CIAM (Customer Identity and Access Management) implementation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMatrix Services\n\n\u003cul\u003e\n\u003cli\u003eAssess the security and integrity of Matrix-based services, including communication and data flow between clients and servers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\u003cbr\u003e\n      - e.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eP5 vulnerabilities\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\u003c/li\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003cli\u003eALL forms of social Engineering\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in  \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowds Terms \u0026amp; Conditions\u003c/a\u003e that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws and the \u003ca href=\"https://www.onersac.com/Membership/Terms-of-Service\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRSAC Terms of Service\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b794b40f-9710-4029-8d49-ab8402cf3fb3","name":"In Scope","targets":[{"id":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6","uri":"https://portal.onersac.com","name":"RSAC Membership Application","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8bba217a-6d91-48ad-9a63-e154be438899","sortOrder":0},"sortOrder":0,"tags":[{"id":"9ffd297c-4781-4777-94cf-ef4e2ddda266","name":"C#","targetId":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"12660d4f-13b6-41a1-91c9-26a4c12b4ea6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch3\u003eTarget Information\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRSAC Membership Application:\u003c/strong\u003e\nThe membership application gives cyber security professionals access to RSAC content and their peers to\nhelp them be more effective in their jobs.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"53889660-1956-463e-996f-1c426f52c2a7","code":"rsac-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"1b28be70-0514-4862-9f18-15e53f83fa12","startsAt":"2025-09-30T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/7161/e64d/dd36e07b/6e21a0ac6a84812951684a3b8abeca6e_RSAC_square_1000x1000.jpg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-09-30T18:00:00.219Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/rsac-vdp-pro","changelogs":"/engagements/rsac-vdp-pro/changelog","submissions":null,"announcements":"/engagements/rsac-vdp-pro/announcements","hallOfFame":"/engagements/rsac-vdp-pro/hall_of_fames","crowdstream":"/engagements/rsac-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/rsac-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=rsac-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/rsac-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/rsac-vdp-pro/changelog","publishedAt":"2025-10-09T20:54:55.161Z","engagementChangelogUrl":"/engagements/rsac-vdp-pro/changelog/0083959e-e0b6-4a7d-aee3-40cb5fa66999","createUserFeedbacksUrl":"/engagements/rsac-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/rsac-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}