{"id":"6c4b1bbe-0f75-49e9-b4fe-cd26411d1722","engagementId":"2f97f161-24bd-42a0-a6eb-fa67fb88b5c7","data":{"brief":{"id":"2f75bd3c-f692-480b-b9eb-14f359495bbe","name":"Sky Italy Vulnerability Disclosure Program","tagline":"Sky is one of Europe’s leading media and entertainment companies and is part of Comcast Corporation, a global media and technology company that connects people to moments and experiences that matter.","description":"\u003cp\u003eWith 24 million customers across six countries, Sky is Europe’s leading media and entertainment company and is proud to be part of the Comcast group. Our 32,000 employees help connect our customers to the very best entertainment, sports, news, arts and to our own local, original content.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Sky believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"ef2b9ee7-7f73-4978-9530-ad18bbf3f902","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorised on the targets listed as in scope. Any domain/property of Sky Group not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Sky Group, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eOut-of-Scope:\u003c/h2\u003e\n\n\u003ch3\u003eOOS Sky Subsidiaries\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eNBCUniversal (Please report all NBCU findings directly to cyber@nbcuni.com)\u003c/li\u003e\n\u003cli\u003eComcast\u003c/li\u003e\n\u003cli\u003eSky UK/ROI (Please report all Sky Italy findings directly to the Sky UK/ROI VDP programme)\u003c/li\u003e\n\u003cli\u003eSky DACH (Please report all Sky Italy findings directly to the Sky DACH VDP programme)\u003c/li\u003e\n\u003cli\u003eVulnerabilities in the following IP addresses: \u003cspan class=\"rp-resources__download-link bc-m-0 bc-icon bc-icon--after cc-icon--download\" data-tooltip-id=\"3498ac38-f753-4bc1-a2b8-9d6985f1e5ee\"\u003e\u003ca href=\"https://bugcrowd.com/engagements/sky-plc-mbb-og1/attachments/3498ac38-f753-4bc1-a2b8-9d6985f1e5ee\" download\u003eSky Excluded IPs.xlsx\u003c/a\u003e\u003c/span\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOOS Submission Types:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e3rd party endpoints\u003c/li\u003e\n\u003cli\u003e3rd party Sky Brand licensing\u003c/li\u003e\n\u003cli\u003eMarketing/Analytics endpoints\u003c/li\u003e\n\u003cli\u003eServer security misconfigurations with no impact (ex. Exposed instances with no sensitive data present)\u003c/li\u003e\n\u003cli\u003eEmail spoofing issues (e.g., SPF, DKIM, DMARC)\u003c/li\u003e\n\u003cli\u003eAutomated scan reports or search engine results (ie, Shodan) without valid proof of concept\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated.\u003c/li\u003e\n\u003cli\u003eSelf-Client-side injection (XSS, Angular, Vue, HTML...) and any XSS that requires Flash. Flash is disabled by default in most modern browsers, thus significantly reducing the attack surface and associated risk.\u003c/li\u003e\n\u003cli\u003eCORS without exploitation.\u003c/li\u003e\n\u003cli\u003eWe'll accept notifications of XSS due to Swagger-UI, but they're not eligible for bounty. It will be considered as P5 Informational. \u003c/li\u003e\n\u003cli\u003eExposed credentials that are either no longer valid, or do not pose a risk to an in-scope asset.\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact, or where the only impact is exhausting of API quotas\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affect users of outdated or unpatched browsers\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g., Stack Traces, application, or server errors) without proof of vulnerability or risk\u003c/li\u003e\n\u003cli\u003eSubmissions for 3rd party code where Sky Group is not responsible for the code.\u003c/li\u003e\n\u003cli\u003eSSL/TLS protocol scan reports reporting purported vulnerable protocol versions or handshakes\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy, HttpOnly or Secure flags on cookies.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOOS Activity Types:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eLoad Testing (DoS, DDoS, wireless jamming, etc.)\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eBanner Grabbing, Scanner Outputs, Password Complexity, User Enumeration, Software version disclosure, Descriptive error messages or headers (e.g. stack traces, application or server errors)\u003c/li\u003e\n\u003cli\u003eTabnabbing.\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.\u003c/li\u003e\n\u003cli\u003eAccount lockout, login, or forgot password page brute force\u003c/li\u003e\n\u003cli\u003eRate limiting issues on non-authentication endpoints/Anti-Automation.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePublicly accessible login panels unless proven security Impact.\u003c/li\u003e\n\u003cli\u003eAny activity that could disrupt our service (DoS), including but not limited to inundating support services with invalid requests.\u003c/li\u003e\n\u003cli\u003eThe customer leaked credentials found in Darkweb or any OSINT tools.\u003c/li\u003e\n\u003cli\u003eSocial engineering attacks, including those targeting or impersonating internal employees by any means (e.g. customer service chat features, social media, personal domains, etc.)\u003c/li\u003e\n\u003cli\u003eBe a current employee of Sky Group or its affiliates or subsidiaries or an employee who has left Sky Group or its affiliates or subsidiaries within the past 12 months.\u003c/li\u003e\n\u003cli\u003eProtocol-specific flaws and open ports or services without an accompanying proof-of-concept demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eTheoretical security issues without any POC\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eHardware Out Of Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhysical tampering of the device (I/O devices such as USB, SIM, and SD card slots are in scope)\u003c/li\u003e\n\u003cli\u003eSubmissions that require an attacker to physically open the case, including removing screws or breaking plastic casing (open chassis) to gain access to the internal hardware of a device.\u003c/li\u003e\n\u003cli\u003eVulnerabilities in pre-release product versions (e.g., Beta, Release candidate).\u003c/li\u003e\n\u003cli\u003eVulnerabilities in product versions are no longer under active support.\u003c/li\u003e\n\u003cli\u003eVulnerabilities are already known to Sky Group. However, if you are the first external security researcher to identify and report a previously known vulnerability, you may still be eligible for a bounty award.\u003c/li\u003e\n\u003cli\u003eSubmissions that utilise third-party websites or tools for cracking or validating secrets, passwords, keys or tokens.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eAccess/Traffic Identification\u003c/h2\u003e\n\n\u003ch3\u003eIP address\u003c/h3\u003e\n\n\u003cp\u003ePlease provide your IP address in the report while submitting the P1/P2 finding.\u003c/p\u003e\n\n\u003ch3\u003eCustom User-Agent Header\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behaviour:\u003c/p\u003e\n\n\u003cp\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/p\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider them as in scope after 30 days have gone by\n\n\u003cul\u003e\n\u003cli\u003e e.g: N-day released on 01/01/2024, we would consider it in-scope on 01/31/2024\u003cbr\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eStolen/Breached Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites, you can report it to this engagement. However, be aware that it is only eligible for points-based compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0db074e1-edc7-4adf-bbe3-5493cf1938d4","name":"In scope","targets":[{"id":"5dd7b8ef-8d8c-4395-b31d-4014cf9c3ef7","uri":"","name":"All internet facing Sky Italy assets ","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"54d9bdb5-b46b-4cf1-9f07-ac5fad46c64e","sortOrder":0},"sortOrder":0,"tags":[{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"5dd7b8ef-8d8c-4395-b31d-4014cf9c3ef7"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5dd7b8ef-8d8c-4395-b31d-4014cf9c3ef7"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"5dc4b15a-ba0c-4660-962d-04861c3af3cc","p1MaxCents":100000,"p1MinCents":50000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":500,"max":1000},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"c6187a3e-b1ae-48f8-9c6f-61313084a23a","name":"Subscriber IP Ranges/Hostnames (Out Of Scope)","targets":[{"id":"4e275f83-4160-421f-8e00-e6155379e706","uri":"","name":"*skybroadband.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f0bf273f-f533-47a8-ab28-0464e850a125","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"03492de9-e023-498b-b788-a6c5a62e7c76","uri":"","name":"*skybet.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"98dcf2e6-f29e-4b56-8dd7-0db2f4992aa0","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"2556e9d1-99db-4094-8b95-ca8af9d13ca2","uri":"","name":"*skynewsarabia.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c0b7a1c7-e085-44b0-8be8-b03f5ba0562c","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"c5d2a0e4-ba3c-43cb-bd8f-82e4537c5a1a","uri":"","name":"*skynews.com.au","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8764d590-3e2a-4036-8c2b-b812ea502d4a","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"a3ec036c-269a-4b1b-b137-930c67c7b02f","uri":"","name":"*safetytraining.sky.it","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"63fdd6c4-b482-4df7-bbf9-52b18e5212d5","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"313e3638-76ab-4ae6-bd32-dad7032942c5","uri":"","name":"All internet facing Sky UK/ROI assets","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b7231aa6-0987-4b5d-8669-fab2f832cf88","sortOrder":5},"sortOrder":5,"tags":[{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"313e3638-76ab-4ae6-bd32-dad7032942c5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"313e3638-76ab-4ae6-bd32-dad7032942c5"}],"recentChangeFlags":null},{"id":"4fd0fc5e-0752-40c9-9426-5e5ab13e34a5","uri":"","name":"All internet facing Sky DACH assets","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f8bb1821-176e-4dd5-90d2-069ffb0342e0","sortOrder":6},"sortOrder":6,"tags":[{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"4fd0fc5e-0752-40c9-9426-5e5ab13e34a5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4fd0fc5e-0752-40c9-9426-5e5ab13e34a5"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThe following IPs belong to our subscribers and are managed on their end.\u003cbr\u003e\nThese are explicitly set as OOS and not to be tested, even if the hostnames resolve to .sky.\u003c/p\u003e\n\n\u003cp\u003eEverything (including any IP) that resolves to the hostname skybroadband.com is out of scope as these are customer hosted sites we do not own.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"3498ac38-f753-4bc1-a2b8-9d6985f1e5ee","attachmentPath":"https://bugcrowd.com/engagements/sky-plc-mbb-og1/attachments/3498ac38-f753-4bc1-a2b8-9d6985f1e5ee","name":"Sky%20Excluded%20IPs.xlsx","filename":"Sky%20Excluded%20IPs.xlsx","description":null,"icon":"fileOther","size":26070,"sizeLabel":"25.5 KB","uploadedAt":"7 Jan 2026","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/sky-plc-mbb-og1/attachments/3498ac38-f753-4bc1-a2b8-9d6985f1e5ee"}],"engagement":{"id":"2f97f161-24bd-42a0-a6eb-fa67fb88b5c7","code":"sky-plc-mbb-og1","state":"in_progress","endsAt":null,"bountyId":"1af0cc1f-44ee-419c-8a74-f32c93961888","startsAt":"2026-01-01T06:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Entertainment","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/b253/5718/657f80d9/165106f96a9871c5b193a2db838a4462_sky.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-01-01T06:00:00.093Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/sky-plc-mbb-og1","changelogs":"/engagements/sky-plc-mbb-og1/changelog","submissions":null,"announcements":"/engagements/sky-plc-mbb-og1/announcements","hallOfFame":"/engagements/sky-plc-mbb-og1/hall_of_fames","crowdstream":"/engagements/sky-plc-mbb-og1/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/sky-plc-mbb-og1/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=sky-plc-mbb-og1\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/sky-plc-mbb-og1/engagement_subscribers","engagementChangelogsUrl":"/engagements/sky-plc-mbb-og1/changelog","publishedAt":"2026-01-08T15:31:56.624Z","engagementChangelogUrl":"/engagements/sky-plc-mbb-og1/changelog/6c4b1bbe-0f75-49e9-b4fe-cd26411d1722","createUserFeedbacksUrl":"/engagements/sky-plc-mbb-og1/feedbacks","engagementCrowdstreamUrl":"/engagements/sky-plc-mbb-og1/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}