{"id":"11747c63-290e-45ee-a503-16741f4330f1","engagementId":"ea8d6a30-40de-4764-aee4-1e03b9956cb8","data":{"brief":{"id":"7d2b2b2b-4063-4e67-aa6d-cac4749c12a1","name":"Service NSW Vulnerability Disclosure Program","tagline":"Service NSW values the positive impact security researchers have on our ability to provide safe and secure services to our customers.","description":"\u003ch2\u003eOur approach to vulnerability disclosure\u003c/h2\u003e\n\n\u003cp\u003eService NSW is dedicated to providing safe and secure services to its customers and greatly values the contributions of security researchers. Through its partnership with Bugcrowd, Service NSW welcomes all vulnerability disclosure reports. Service NSW is committed to transparent collaboration with researchers to validate and remediate reported vulnerabilities, recognising their vital role in enhancing customer safety.\u003c/p\u003e\n\n\u003cp\u003eWe encourage you to submit details of suspected vulnerabilities across any asset owned, controlled, operated, or maintained by Service NSW.\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritisation/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a detailed explanation will be provided to the researcher, along with the opportunity to appeal and make a case for a higher priority.\u003c/p\u003e\n\n\u003cp\u003eIf you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Service NSW, you can report it to this engagement.\u003c/p\u003e\n\n\u003cp\u003eService NSW utilises several third-party providers and services which are considered out of scope for this program. Security testing against systems not owned by Service NSW is not authorised. If you identify issues within these services, it is highly recommended to report them directly to the third-party. For issues identified in other Australian government services, please use the reporting function hosted at \u003ca href=\"https://www.cyber.gov.au/report-and-recover/report\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCyber.gov.au\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eInput Validation Bypass:\u003c/strong\u003e Circumventing client-side or server-side input validation, including injection of malicious or unexpected input into forms.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUnauthorised Credential Association:\u003c/strong\u003e Linking identity credentials (e.g., license, Medicare, identity document) to an account without legitimate holding, avoiding brute-force or high-volume testing, and without using real customer data.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAuthentication \u0026amp; Session Weaknesses:\u003c/strong\u003e Issues such as MFA bypass, session fixation, or token prediction.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccess Control Issues:\u003c/strong\u003e Bypassing Identity and Access Management (IAM) controls, especially around access to user data, administrative functions, or leading to Insecure Direct Object References (IDOR).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eMisconfigurations \u0026amp; Weak Cryptography:\u003c/strong\u003e Identification of misconfigured subdomains, APIs, endpoints, broken cryptography, or certificate misconfigurations that weaken transport security.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThe Service NSW platform is designed to handle sensitive data and documents related to government services.\u003c/p\u003e\n\n\u003cp\u003eWhile automated tools are not prohibited, unattended or high-volume scanning is not permitted. Please rate-limit your requests (e.g., no more than 5 requests per second per endpoint). Persistent scanning will be blocked by Service NSW security systems.\u003c/p\u003e\n\n\u003ch3\u003eTraffic Identification\u003c/h3\u003e\n\n\u003cp\u003eWhere possible, include \u003ccode\u003eUA-Bugcrowd\u003c/code\u003e in the \u003ccode\u003eUser-Agent\u003c/code\u003e string to help identify security testing traffic.\u003c/p\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email address. For more information regarding \u003ccode\u003e@bugcrowdninja\u003c/code\u003e email addresses, please refer to \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cp\u003eService NSW requests that researchers make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing. Please do not target or interact with real customer data or live customer accounts during testing.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCustomer Safety: Testing must never interfere with a user’s ability to access or use a Service NSW service.\u003c/li\u003e\n\u003cli\u003eData Exfiltration: You must not exfiltrate any data under any circumstances.\u003c/li\u003e\n\u003cli\u003eProcessing Payments: Refunds cannot be issued.\u003c/li\u003e\n\u003cli\u003eMass spam or bulk content injection without prior approval.\u003c/li\u003e\n\u003cli\u003eUse of production-facing communication channels such as customer feedback or complaint forms.\u003c/li\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003cli\u003eVerification emails/SMS messages\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePotential Post-exploitation Scenarios\u003c/strong\u003e: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites, please report them immediately without attempting to use or validate them. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorised in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCoordinated Disclosure:\u003c/h2\u003e\n\n\u003cp\u003eService NSW commits to allowing researchers to publish mutually agreed information about a vulnerability after it has been fixed. Service NSW must give explicit permission to disclose in the submission record. This applies to all the submissions for the program, regardless of validity or acceptance. Once the vulnerability is allowed to be disclosed on Bugcrowd’s platform, the Researcher can disclose the vulnerability publicly as long as it adheres to the agreed type of disclosure - limited or full, and any other parameters agreed for the disclosure.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"d797f68b-751f-467c-8bd5-88baf042b4d0","name":"Service NSW","targets":[{"id":"149a3f16-1c27-4eaa-8cb9-93c17b9c7bd0","uri":"https://account.service.nsw.gov.au","name":"*.account.service.nsw.gov.au","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"58e9ee1f-8c36-4a0a-b875-554a953e0ae6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"149a3f16-1c27-4eaa-8cb9-93c17b9c7bd0"}],"recentChangeFlags":null},{"id":"32dcafd4-963c-4e3a-b597-d98f512f3b46","uri":"","name":"*.service.nsw.gov.au","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c1695cc2-35f1-4dc9-a28e-2a8d3dce5104","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"32dcafd4-963c-4e3a-b597-d98f512f3b46"}],"recentChangeFlags":null},{"id":"3c1bbf60-8c22-47aa-8f11-f82034a4f366","uri":null,"name":"*.api.service.nsw.gov.au","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"502094cb-a878-4eb9-9760-a28cddc40d50","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"3c1bbf60-8c22-47aa-8f11-f82034a4f366"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"3c1bbf60-8c22-47aa-8f11-f82034a4f366"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThe Service NSW (SNSW) platform enables users to get information and access to many of the following state Government services, which include but are not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGrants, Rebates and other government support\u003c/li\u003e\n\u003cli\u003eEducation and training \u003c/li\u003e\n\u003cli\u003ePay Fines \u003c/li\u003e\n\u003cli\u003eLicense and Registration for Vehicles, Boats and other vehicles \u003c/li\u003e\n\u003cli\u003ePermits for hunting and fishing \u003c/li\u003e\n\u003cli\u003eAccess to Healthcare and Disability Services \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThere is much much more so please review the site and each section for opportunities to hunt!\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"675db469-4b1e-45e2-b42f-f468a0ed6177","name":"Out of Scope","targets":[{"id":"fd9e99c1-a423-4c4b-920a-23cb29dd3fe6","uri":"","name":"*nsw.gov.au","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6e1a241c-e237-4019-9ce7-0959fcd86e53","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fd9e99c1-a423-4c4b-920a-23cb29dd3fe6"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"ea8d6a30-40de-4764-aee4-1e03b9956cb8","code":"service-nsw-vdp","state":"in_progress","endsAt":null,"bountyId":"59865a4c-9c0d-4f1f-9e11-76fe61655d1f","startsAt":"2019-07-17T00:19:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/6ce7/1a6c/94a9123d/675b4474d820049805e7e2bc84ee1236_mAlsVQsn_400x400.jpg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-07-17T00:19:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/service-nsw-vdp","changelogs":"/engagements/service-nsw-vdp/changelog","submissions":null,"announcements":"/engagements/service-nsw-vdp/announcements","hallOfFame":"/engagements/service-nsw-vdp/hall_of_fames","crowdstream":"/engagements/service-nsw-vdp/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/service-nsw-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=service-nsw-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/service-nsw-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/service-nsw-vdp/changelog","publishedAt":"2025-08-14T00:08:30.024Z","engagementChangelogUrl":"/engagements/service-nsw-vdp/changelog/11747c63-290e-45ee-a503-16741f4330f1","createUserFeedbacksUrl":"/engagements/service-nsw-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/service-nsw-vdp/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}