{"id":"edd9ae05-5b64-40ed-b7fc-ec8bd70979ea","engagementId":"37e45e9f-9f0a-495b-8354-a90df686dc31","data":{"brief":{"id":"9fb212f9-3718-462a-93bc-8f3b88fb0993","name":"SnapNames Bug Bounty","tagline":"SnapNames is the web's domain name marketplace of choice throughout the world. We bring businesses global access to already-registered domains with the convenience of online and mobile shopping.","description":"\u003cp\u003eNo technology is perfect, and SnapNames believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our targets. Good luck and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEligibility\u003c/h2\u003e\n\n\u003cp\u003eYou may not participate in this program if you are an employee or family member of an employee, or a current vendor or employee of such vendor of Newfold Digital and any of its subsidiaries. You are also prohibited from participating if you are (i) in a country or territory that is the target of U.S. sanctions (including Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine), (ii) designated as a Specially Designated National or Blocked Person by the U.S. Department of the Treasury’s Office of Foreign Assets Control or otherwise owned, controlled, or acting on behalf of such a person or entity, or (iii) otherwise a prohibited party under U.S. trade and export control laws.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eThe program relies on CVSS to evaluate impact and determine reward allocations. It is essential to highlight that the priority of a vulnerability might be altered due to following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe severity of the vulnerability (CVSS rating)\u003c/li\u003e\n\u003cli\u003eThe likelihood of exploit\u003c/li\u003e\n\u003cli\u003eThe impact of exploit\u003c/li\u003e\n\u003cli\u003eAny other factor at our discretion\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCVSS Score\u003c/th\u003e\n\u003cth\u003eVRT Classification\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e9.0-10.0\u003c/td\u003e\n\u003ctd\u003eP1-Critical\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e7.0-8.9\u003c/td\u003e\n\u003ctd\u003eP2-High\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e4.0-6.9\u003c/td\u003e\n\u003ctd\u003eP3-Medium\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e2.0-3.9\u003c/td\u003e\n\u003ctd\u003eP4-Low\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e0.0-1.9\u003c/td\u003e\n\u003ctd\u003eP5-Informational\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eWe reserve the right to make any final determination of rating levels for any reported vulnerability. Researchers must provide a fully working non-malicious proof of concept that demonstrates a valid security impact to qualify for rewards. \u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eYou are able to self-sign up for credentials. You will need a credit card in order to do so. Please note that gift cards may not work as the sign up process requires:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e\u003cp\u003eTwo temporary holds placed on your credit card, under $2.00, from Snapnames.com. Please provide these amounts. Those amounts will drop off in 3-5 days. If you do not see these holds, you may need to contact your bank/card provider and request they provide them to you.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFor additional security, secondary verification is now required on all accounts. For this, we require the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA copy of a valid, government-issued photo identification (front and back) which matches the name on the account.\u003c/li\u003e\n\u003cli\u003eAn image of you in possession of said identification. Please be sure to include your face in this image so that we may confirm your identity.\nYou can send this to mysupport@snapnames.com.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules \u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eDo not create multiple accounts for testing purposes within SnapNames applications and services. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eRefrain from using brute force techniques to assess API rate limiting or other functionalities. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePhishing, vishing, smishing, or any other forms of social engineering are strictly prohibited. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eEnsure efforts are made to avoid privacy violations, data destruction, and disruption or degradation of service. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOnly interact with accounts you own or have explicit permission to use.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eUnblocking restricted accounts is not guaranteed. Requests for review can be submitted through Bugcrowd for consideration by the SnapNames InfoSec team. Testing is only permitted on components directly controlled by our program; third-party assets are excluded. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eVulnerabilities found on different domains/target may be controlled by the same platform code. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you find the same bug on a different target, prior to the report reaching a triaged state, file it within the existing report. Any reports filed separately while we are actively working to resolve the issue will be treated as a duplicate. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eInteracting with real customers or real customer accounts is forbidden. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWhen a vulnerability consists of different parameters but having the same endpoint, please group this together in the same report else will be considered as duplicate. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty (Ex: Centralized vulnerable parameters). \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCross-Site Scripting (XSS) attacks are considered at maximum a medium severity. \u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not test the support functionality\u003c/li\u003e\n\u003cli\u003eSubdomain takeovers. Please submit any subdomain takeovers to the \u003ca href=\"https://bugcrowd.com/snapnames-vdp\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSnapNames VDP\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCache poisoning\u003c/li\u003e\n\u003cli\u003eNo DMARC, nor SPF \u003c/li\u003e\n\u003cli\u003eDos/DDos (Rate Limiting) \u003c/li\u003e\n\u003cli\u003eOAuth session token is not invalidated on logout or password change/reset\u003c/li\u003e\n\u003cli\u003eOpen redirect vulnerabilities \u003c/li\u003e\n\u003cli\u003eError messages (e.g. verbose error messages, stack traces, application or server errors, version disclosure) \u003c/li\u003e\n\u003cli\u003eClickjacking \u003c/li\u003e\n\u003cli\u003eMissing or misconfigured HTTP security header \u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning \u003c/li\u003e\n\u003cli\u003eCloudflare related issues \u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted\u003c/li\u003e\n\u003cli\u003eBroken links hosted on our website\u003c/li\u003e\n\u003cli\u003eSecrets such as API keys or passwords obtained from external aggregation/indexed data sources (e.g., dehashed.com or intelx.io)\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with non-sensitive actions (including logout CSRF) \u003c/li\u003e\n\u003cli\u003eRecently disclosed (\u0026lt;30 days) zero-day vulnerabilities\u003c/li\u003e\n\u003cli\u003ePlease do not test chatboxes on the applications, etc. \u003c/li\u003e\n\u003cli\u003eUse of third-party vulnerable components \u003c/li\u003e\n\u003cli\u003eAnti Automation attacks, missing captcha, missing rate limiting, HTTP headers, SSL/TLS configuration and missing Secure flag on cookies are out of scope\u003c/li\u003e\n\u003cli\u003eAny source code disclosure \u003c/li\u003e\n\u003cli\u003eInfo.php (without providing an exploitable scenario) \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"5e1dd435-3e64-4715-bbe1-b9a1cb7abd95","name":"In Scope","targets":[{"id":"e89adc5f-c7b5-4e33-9cbc-b0d256db24b5","uri":"https://snapnames.com/","name":"https://snapnames.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8185c7ea-c3c4-4df3-8f66-56cdc26aa8f8","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e89adc5f-c7b5-4e33-9cbc-b0d256db24b5"},{"id":"1fa83629-2fba-4fda-8839-03b25db67d1d","name":"Oracle Database","targetId":"e89adc5f-c7b5-4e33-9cbc-b0d256db24b5"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"e89adc5f-c7b5-4e33-9cbc-b0d256db24b5"},{"id":"a5a8125d-2e24-4979-a994-d67089f0909b","name":"Apache Tomcat","targetId":"e89adc5f-c7b5-4e33-9cbc-b0d256db24b5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e89adc5f-c7b5-4e33-9cbc-b0d256db24b5"}],"recentChangeFlags":null},{"id":"2ee00371-f784-4f36-9a89-33f0393db918","uri":"https://www.namejet.com/","name":"https://www.namejet.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"db3724ec-fa87-4dff-8527-e3eda515d30f","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"2ee00371-f784-4f36-9a89-33f0393db918"},{"id":"1fa83629-2fba-4fda-8839-03b25db67d1d","name":"Oracle Database","targetId":"2ee00371-f784-4f36-9a89-33f0393db918"},{"id":"a5a8125d-2e24-4979-a994-d67089f0909b","name":"Apache Tomcat","targetId":"2ee00371-f784-4f36-9a89-33f0393db918"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2ee00371-f784-4f36-9a89-33f0393db918"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"5bfd9831-01e8-422e-bb9c-dd0ed251c189","p1MaxCents":200000,"p1MinCents":120000,"p2MaxCents":100000,"p2MinCents":50000,"p3MaxCents":45000,"p3MinCents":25000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch3\u003eTarget Information\u003c/h3\u003e\n\n\u003cp\u003eAftermarket domain name applications like \u003cstrong\u003eSnapNames\u003c/strong\u003e and \u003cstrong\u003eNameJet\u003c/strong\u003e help businesses and individuals acquire previously owned domain names that are expiring or about to be deleted. By leveraging exclusive partnerships with top registrars and using advanced technology, they monitor and capture high-demand domain names before others can. This service ensures clients get the best chance to secure valuable or brand-specific domain names even if they are already taken.\u003c/p\u003e","rewardRangeData":{"1":{"min":1200,"max":2000},"2":{"min":500,"max":1000},"3":{"min":250,"max":450},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"db0743fd-d163-4609-b9a9-9485a16dd07b","name":"Out Of Scope","targets":[{"id":"886c9cf4-4b02-4a1b-936f-a98e8b173fd2","uri":"https://www.*.snapnames.com","name":"*.snapnames.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"63dd3a1c-ff88-44a2-b352-0bf4a812190b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"886c9cf4-4b02-4a1b-936f-a98e8b173fd2"}],"recentChangeFlags":null},{"id":"3d9fcfdb-0698-4370-bd21-b53b895c6ba3","uri":"https://www.namejet.com","name":"*.namejet.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8ffce248-b60e-4676-b753-69c6192f6b66","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"3d9fcfdb-0698-4370-bd21-b53b895c6ba3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3d9fcfdb-0698-4370-bd21-b53b895c6ba3"}],"recentChangeFlags":null},{"id":"9efd67b3-5352-40a8-a8fa-9d86e2a3b4ab","uri":"","name":"*.buydomains.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c7ae0b23-9309-409b-9594-4a24f4936e9e","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9efd67b3-5352-40a8-a8fa-9d86e2a3b4ab"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAny asset not explicitly listed in scope above falls outside this program. If you have found a vulnerability on an asset not covered here, we still want to hear from you — please submit it through our Vulnerability Disclosure Program using the relevant link below:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://namejet.com/vulnerability-disclosure.action\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNamejet\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://snapnames.com/vulnerability-disclosure.action\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSnapnames\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://buydomains.com/report-ethical-hacking\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBuyDomains\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eReports submitted through these forms will be reviewed by our security team.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"37e45e9f-9f0a-495b-8354-a90df686dc31","code":"snapnames","state":"in_progress","endsAt":null,"bountyId":"d8c19b94-0f9f-48dd-9c3e-f5d5264f8922","startsAt":"2021-01-14T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/743e/dfa6/1c995120/d4707f93ad61b32631de989e40ff9237_snapnames.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":false,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"ngpt","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-01-14T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/snapnames","changelogs":"/engagements/snapnames/changelog","submissions":null,"announcements":"/engagements/snapnames/announcements","hallOfFame":"/engagements/snapnames/hall_of_fames","crowdstream":"/engagements/snapnames/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/snapnames/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=snapnames\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/snapnames/engagement_subscribers","engagementChangelogsUrl":"/engagements/snapnames/changelog","publishedAt":"2026-04-24T06:22:22.654Z","engagementChangelogUrl":"/engagements/snapnames/changelog/edd9ae05-5b64-40ed-b7fc-ec8bd70979ea","createUserFeedbacksUrl":"/engagements/snapnames/feedbacks","engagementCrowdstreamUrl":"/engagements/snapnames/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}