{"id":"15ecb6b8-00f6-4b9e-a854-911e5c976a6e","engagementId":"80fb36e8-8d97-476a-b40a-ebac6dfc1ac1","data":{"brief":{"id":"a10dce9c-6eb0-4b97-8b16-24d7cea2f471","name":"Sophos","tagline":"Responsible disclosure with rewards up to US$80,000","description":"\u003ch2\u003eProgram Overview\u003c/h2\u003e\n\n\u003cp\u003eAt Sophos, we understand the effort that goes into security research. To show our appreciation to researchers, who help keep our products and our customers safe, we are glad to introduce a Responsible Disclosure Program to provide recognition and rewards for responsibly disclosed vulnerabilities. \u003c/p\u003e\n\n\u003cp\u003eSophos rewards the responsible disclosure of any identified and confirmed security vulnerability that could be used to compromise the confidentiality, integrity, or availability of Sophos products, as well as services and infrastructure impacting Sophos' or users' data.\u003c/p\u003e\n\n\u003cp\u003eIn general no credentials or product keys will be provided for this program - all testing is to be performed using self-provisioned credentials against legally obtained Sophos products, including free trials. See the section \u003cem\u003eCredentials\u003c/em\u003e for more details.\u003c/p\u003e\n\n\u003cp\u003eThe severity of submissions will be determined using CVSSv3.1 according to Sophos' internal standard.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch2\u003eResearch\u003c/h2\u003e\n\n\u003cp\u003eResearchers should use test accounts (cf. \u003cem\u003eCredentials\u003c/em\u003e below) or test systems where possible, such that the security and privacy of real users is protected. At all times, make a good faith effort to avoid privacy violations as well as destruction, interruption or segregation of Sophos services. Do not modify or destroy data that does not belong to you.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePotentially destructive tests, including denial of service, require prior written consent by Sophos.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eReach out to \u003ccode\u003esecurity-alert@sophos.com\u003c/code\u003e, if a potentially destructive test on a production system is required to confirm a finding.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eDenial of Service testing against Sophos Central is explicitly prohibited and will not be approved at this time.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eReporting\u003c/h2\u003e\n\n\u003cp\u003eRewards or recognition require that the Sophos security team can reproduce and verify an issue and that the security impact is clear.\u003c/p\u003e\n\n\u003cp\u003eReproduction steps need to be clear, and may include screenshots, videos, scripts, etc.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDO NOT\u003c/strong\u003e use the output from automated scanners and tools as the entire vulnerability report.\u003c/p\u003e\n\n\u003ch2\u003eRewards\u003c/h2\u003e\n\n\u003cp\u003eRewards will be provided according to the rules of this bug bounty program as outlined above. At the discretion of Sophos, quality, creativity, or novelty of submissions may modify payouts within a given range.\u003c/p\u003e\n\n\u003cp\u003eIn case of multiple reports about the same issue, Sophos will reward the earliest submission, regardless of how the issue was reported.\u003c/p\u003e\n\n\u003ch3\u003eIssues in Security Features\u003c/h3\u003e\n\n\u003cp\u003eReports about bugs or limitations in Sophos product security features, such as the ability to bypass a particular filter, are out of scope for the Sophos Bug Bounty Program and not eligible for rewards upon acceptance.\u003c/p\u003e\n\n\u003cp\u003eValid reports about novel security feature bypasses will be forwarded to the respective product team for review.\u003c/p\u003e\n\n\u003cp\u003eAt the sole discretion of the Sophos Product Management team, individual reports like these may be rewarded on a case by case basis.\u003c/p\u003e\n\n\u003cp\u003eFalse negatives (undetected malware) are excluded from the program. However, we encourage you to submit any false negatives via \u003ca href=\"https://support.sophos.com/support/s/filesubmission\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://support.sophos.com/support/s/filesubmission\u003c/a\u003e or email to \u003ccode\u003esamples@sophos.com\u003c/code\u003e.\u003c/p\u003e\n\n\u003ch2\u003eResponsible Disclosure\u003c/h2\u003e\n\n\u003cp\u003eSophos takes responsibility for disclosing product vulnerabilities to customers. To encourage responsible disclosure, we ask that all researchers comply with the following Responsible Disclosure Guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAllow Sophos an opportunity to both correct and disclose a vulnerability first (including any CVE, if applicable) within a reasonable time frame.\u003c/li\u003e\n\u003cli\u003eAllow Sophos' customers 30 days to install the security patch before disclosing vulnerability details to anyone.\u003c/li\u003e\n\u003cli\u003eCoordinate with Sophos on any publication of vulnerability details.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eSophos advises its customers that those who exploit security systems often do so by reverse engineering published security updates, and therefore encourages its customers to patch timely.\u003c/p\u003e\n\n\u003cp\u003eFor the full responsible disclosure policy, please refer to and comply with the \u003ca href=\"https://sophos.com/security\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSophos Responsible Disclosure Policy\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eReward Eligibility\u003c/h2\u003e\n\n\u003cp\u003eCurrent employees or contractors of a Sophos Group entity are not eligible to participate in the program. Former employees and contractors are eligible to participate in the program only, if\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003ethey have left the Sophos Group entity more than 1 year prior to submission, and\u003c/li\u003e\n\u003cli\u003ethey are not making use of, or referring to, any non-public Sophos information obtained when they were an employee or contractor.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003ch3\u003eTesting Credentials\u003c/h3\u003e\n\n\u003cp\u003eFor testing services and products that require credentials, please create an account on your own using your \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email address. Your bugcrowdninja email address is your username \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e. All emails will go to the email address associated with your account.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eIn all cases, ensure that the term \u003ccode\u003ebugcrowd\u003c/code\u003e is part of your testing account.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eIf for some reason your IP address or account are banned during your research activity, please contact us at \u003ccode\u003ebugbounty@sophos.com\u003c/code\u003e and we'll restore your access ASAP.\u003c/p\u003e\n\n\u003ch3\u003eCredential Leaks\u003c/h3\u003e\n\n\u003cp\u003eReports about leaked credentials, included but not limited to user names, passwords, cookies, tokens, etc., are \u003cem\u003enot\u003c/em\u003e eligible for reward unless steps are provided on how they can be acquired from a system under direct Sophos control.\u003c/p\u003e\n\n\u003ch2\u003eLEGAL\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eBy engaging or participating in this bug bounty program, you agree to treat the following types of information as Sophos’s confidential information and not divulge to any third person (except disclosure to Sophos through the Bugcrowd platform) any such information until disclosure is approved in writing by Sophos:\u003cbr\u003e\n(i) all information you receive or collect about Sophos and its products, or any of Sophos’s customers during your participation in this program; and/or\u003cbr\u003e\n(ii) vulnerability report and any vulnerability.\u003cbr\u003e\u003cbr\u003e\nDisclosure of Sophos’s confidential information to any third parties before Sophos’s approval forfeits the reward and could disqualify you from participating in this bug bounty program in the future. Please notify Sophos immediately upon discovery of any loss or unauthorized disclosure of confidential information. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must notify Sophos immediately if you: \u003cbr\u003e\n(i) gain access to another person's accounts or data; \u003cbr\u003e\n(ii) destroy any data, or \u003cbr\u003e\n(iii) cause interruption or degradation of Sophos’s infrastructure and services. Additionally, if you encounter personally identifiable information, customer data or other sensitive information, please contact Sophos immediately, and do not retain any copies of such information.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBy submitting your vulnerability report, you perpetually allow Sophos and its affiliates and subsidiaries the unconditional ability to use, modify, create derivative work from, distribute, publish and display information provided in your report or to have others do the same on Sophos’s behalf, and these rights cannot be revoked.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSophos cannot provide a reward if you’re a minor, on a sanctions list, or live in a country that is on a sanctions list.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must comply with all applicable laws in connection with your participation in this program.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAs a participant in this program, you will not be deemed to be in breach of applicable Sophos license provisions so long as your actions are consistent with this bug bounty brief.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"915e0240-2deb-4ac7-a8a9-e72d8080853b","name":"Intercept X Endpoint (Windows) Special Target","targets":[{"id":"688604cf-fdad-477b-bf04-1b724989ee56","uri":"https://www.sophos.com/en-us/products/endpoint-antivirus/free-trial ","name":"Intercept X Endpoint (Windows) - Zero-click RCE","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c789a61e-a59e-4acf-81b2-6f36212fa582","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"2857b811-f2f2-4516-be22-71689af0b6fd","p1MaxCents":8000000,"p1MinCents":8000000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eSophos Endpoint Protection is a multi-component system where some parts run at the highest possible privilege. One of the design goals is to protect users of the endpoint from threats on the network, therefore remote compromise of Endpoint Protection components is of particular concern to Sophos.\u003c/p\u003e\n\n\u003ch4\u003eAttacks meeting \u003cem\u003eALL\u003c/em\u003e of the following conditions are eligible for consideration of a maximum bounty of $80,000:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003etriggering execution of attacker-controlled code\u003c/li\u003e\n\u003cli\u003ein a high privilege context (Administrator or higher for Windows)\u003c/li\u003e\n\u003cli\u003edoing so remotely\u003c/li\u003e\n\u003cli\u003edoing so via Endpoint Protection components\u003c/li\u003e\n\u003cli\u003eno user interaction is necessary\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eClear instructions for how to reproduce the finding are required.\u003c/p\u003e\n\n\u003cp\u003eSome examples of in and out of scope scenarios follow. These are intended to illustrate the above definition, not to limit it. Attacks that meet the definition will be in scope.\u003c/p\u003e\n\n\u003cp\u003eExamples:\u003c/p\u003e\n\n\u003cp\u003eIn-scope examples (all must lead to the attacker able to act as Admin, with no user interaction):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDirect exploitation via an exposed port associated with an Endpoint Protection component.\u003c/li\u003e\n\u003cli\u003eTarget machine receives an email from attacker triggering RCE due to Endpoint Protection processing / parsing.\u003c/li\u003e\n\u003cli\u003eA browser on the endpoint visits a webpage leading to code execution due to Endpoint Protection interactions with the browser or associated network traffic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOut-of-scope examples:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCode execution after connecting via an authorized remote route, e.g. RDP. This is not considered a remote exploit since the RDP connection gives the attacker a presence local to the target.\u003c/li\u003e\n\u003cli\u003eAny attack where a user needs to enter credentials. Attacks where user interaction is required are excluded from this bounty target.\u003c/li\u003e\n\u003cli\u003eAny attack where code execution is obtained but not in the context of Admin.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAll testing can be done with free trial versions \u003ca href=\"https://www.sophos.com/en-us/products/endpoint-antivirus/free-trial\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.sophos.com/en-us/products/endpoint-antivirus/free-trial\u003c/a\u003e of the product on the Windows platform.\u003c/p\u003e\n\n\u003ch5\u003eIMPORTANT. All research should be done on fresh trial versions of Intercept X and when signing up for the trial, ensure your email has bugcrowdninja in the address. For example, tom+bugcrowdninja@gmail.com or bill@bugcrowdninja.com\u003c/h5\u003e\n\n\u003cp\u003eEligible findings are reproducible on fully patched installations of Intercept X. Sophos will not reward issues that are not reproducible in the latest release. Testing should be done on 64-bit Windows only, Windows 10 22H2 (build 19045) or later Windows 11 22H2 (build 22621) or later.\u003c/p\u003e","rewardRangeData":{"1":{"min":80000,"max":80000},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"7ac934ae-76cc-4aa9-b458-66ff2e43ea12","name":"Sophos Central Special Target","targets":[{"id":"37d359c2-ffce-4c68-88ea-7f2ff5a3ed76","uri":"https://central.sophos.com/","name":"Sophos Central (Production) - Special Target","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2a80f695-6af8-4075-ac97-5a460245017c","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"37d359c2-ffce-4c68-88ea-7f2ff5a3ed76"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"37d359c2-ffce-4c68-88ea-7f2ff5a3ed76"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"c750001c-18f1-4e99-b060-61d2545b2337","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eSophos Central is an integrated management platform that enables customers to effectively utilize and oversee the capabilities and synergies of the Sophos products installed in their environments. Additionally, it facilitates the configuration of hosted services designed to safeguard customer assets.\u003c/p\u003e\n\n\u003cp\u003eIt is crucial to prioritize the protection of customer data and other valuable assets at all times.\u003c/p\u003e\n\n\u003cp\u003eThe following categories of issues, which could significantly impact both Sophos customers and the company itself, are eligible for the highest payout if all the respective requirements are met:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eLarge-scale data breach with potential regulatory disclosure requirements\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eInvolving thousands of customer accounts without relying on brute force methods, \u003cem\u003eand\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eAffecting legally relevant customer data, such as high-risk Personally Identifiable Information (PII)\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eComplete, zero-touch, super-admin account takeover\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eImpacting a broad range of super-admin accounts, \u003cem\u003eand\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eNot requiring any user interaction, \u003cem\u003eand\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eOriginating from Sophos, rather than a third-party Identity Provider (IDP)\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDemonstrating full or partial administrator-level access to Sophos production public cloud infrastructure by modifying AWS resources or configurations, particularly those related to Identity and Access Management (IAM)\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDemonstrating privilege escalation by writing arbitrary files on a compute instance outside of legitimate use cases\u003c/strong\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eAll testing can be done with \u003ca href=\"https://www.sophos.com/en-us/products/sophos-central\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003efree trial accounts\u003c/a\u003e on Sophos Central. Reports must include clear steps for reproducing the issue.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eIMPORTANT.\u003c/strong\u003e All research should be done on fresh trial accounts and when signing up for the trial, ensure your email has \u003cem\u003ebugcrowdninja\u003c/em\u003e in the address. For example, \u003ccode\u003etom+bugcrowdninja@gmail.com\u003c/code\u003e or \u003ccode\u003ebill@bugcrowdninja.com\u003c/code\u003e.\u003c/p\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e1f6b1a2-73bd-4ff6-953b-2a94ad341993","name":"Sophos Firewall Special Target","targets":[{"id":"0da98da1-21c4-4264-958a-97e23be8b337","uri":null,"name":"Sophos Firewall (XG/XGS, SFOS) - Pre-auth RCE","category":"iot","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"de07943b-e53e-4704-96e1-2669c986aa14","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"0da98da1-21c4-4264-958a-97e23be8b337"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"0da98da1-21c4-4264-958a-97e23be8b337"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"c750001c-18f1-4e99-b060-61d2545b2337","p1MaxCents":5000000,"p1MinCents":5000000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eSophos Firewall is a next-generation firewall and comprehensive network security platform. It frequently serves as the primary line of defense against threats targeting local networks and their users, placing it under significant scrutiny.\u003c/p\u003e\n\n\u003cp\u003eFindings of critical severity issues that are exploitable at large scale are eligible for the highest reward. Reports are/come with:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAttack Vector: Network (WAN interface only)\u003c/li\u003e\n\u003cli\u003eAttack Complexity: Low (no MitM etc.)\u003c/li\u003e\n\u003cli\u003ePrivileges Required: None (pre-auth only)\u003c/li\u003e\n\u003cli\u003eUser Interaction: None (no phishing, etc.)\u003c/li\u003e\n\u003cli\u003eImpact: Code/command execution as root (CVSSv3+ C:H/I:H/A:H)\u003c/li\u003e\n\u003cli\u003eReproducible on the latest maintenance release of the latest version, as published on MySophos\u003c/li\u003e\n\u003cli\u003eDetailed version information:\n\n\u003cul\u003e\n\u003cli\u003eLogin to the Device Console\u003c/li\u003e\n\u003cli\u003eAt the console\u0026gt; prompt type: “system dia sh ver”\u003c/li\u003e\n\u003cli\u003eAdd the output to the report (screenshots accepted)\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003ePoC code or step by step reproduction instructions\n\n\u003cul\u003e\n\u003cli\u003eMay be in the form of a video\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eTools used to detect the issue, if any\u003c/li\u003e\n\u003cli\u003eInformation on what helped discover the issue most:\n\n\u003cul\u003e\n\u003cli\u003eRoot shell access\u003c/li\u003e\n\u003cli\u003eReverse engineering (decompiled JARs)\u003c/li\u003e\n\u003cli\u003ePreviously published CVE (incl. CVE ID)\u003c/li\u003e\n\u003cli\u003eOther (please elaborate)\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eSource code file and line of the issue, if possible\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eSophos will leverage existing configuration telemetry to assess the probability of an exploit being effective on a large scale. When more than 95% of all devices are proven to run a non-exploitable configuration, the threshold of this target is not met, and the regular reward structure applies.\u003c/p\u003e\n\n\u003cp\u003eAll testing can be done with \u003ca href=\"https://secure2.sophos.com/en-us/products/next-gen-firewall/free-trial.aspx\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003efree trial versions\u003c/a\u003e of the product on any available platform (software/virtual/hardware).\u003c/p\u003e\n\n\u003cp\u003eIMPORTANT. All research should be done on fresh trial versions and when signing up for the trial, ensure your email has \u003cem\u003ebugcrowdninja\u003c/em\u003e in the address. For example, tom+bugcrowdninja@gmail.com or bill@bugcrowdninja.com\u003c/p\u003e\n\n\u003cp\u003eEligible findings are reproducible on fully patched installations of XG Firewall (see https://community.sophos.com/kb/en-us/135415 for details). Sophos will not reward issues that are not reproducible in the latest release.\u003c/p\u003e","rewardRangeData":{"1":{"min":50000,"max":50000},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"2b8feea9-36db-4f41-a6ec-1b5e98f980b4","name":"Premium Bounty Eligible Targets","targets":[{"id":"76f793f2-5ff3-4586-8c36-85e1f7deac5f","uri":"https://central.sophos.com","name":"Sophos Central (Production)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4cac036d-f6e5-4136-b947-a9f233550235","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"76f793f2-5ff3-4586-8c36-85e1f7deac5f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"76f793f2-5ff3-4586-8c36-85e1f7deac5f"}],"recentChangeFlags":null},{"id":"b670dda7-9c80-4b5a-a299-b36849a59496","uri":"https://www.sophos.com/en-us/products/next-gen-firewall","name":"Sophos Firewall (XG/XGS, SFOS)","category":"iot","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c36ee8df-754e-4e79-af16-27fc43e5f5b4","sortOrder":1},"sortOrder":1,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"b670dda7-9c80-4b5a-a299-b36849a59496"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"b670dda7-9c80-4b5a-a299-b36849a59496"}],"recentChangeFlags":null},{"id":"f4ebe2ab-2770-4706-9977-3c6303273004","uri":"https://www.sophos.com/en-us/products/endpoint-antivirus/free-trial","name":"Intercept X Endpoint (Windows)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6ec088f1-596a-44f4-9f3a-aff5eec630fb","sortOrder":2},"sortOrder":2,"tags":[{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"f4ebe2ab-2770-4706-9977-3c6303273004"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"f4ebe2ab-2770-4706-9977-3c6303273004"}],"recentChangeFlags":null},{"id":"def6f9db-cf84-4121-96fb-4413898151c2","uri":"https://www.sophos.com/en-us/products/endpoint-antivirus/free-trial","name":"Intercept X Endpoint (MacOS)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5b240501-5741-439d-b179-5797fa19d6f5","sortOrder":3},"sortOrder":3,"tags":[{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"def6f9db-cf84-4121-96fb-4413898151c2"},{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"def6f9db-cf84-4121-96fb-4413898151c2"}],"recentChangeFlags":null},{"id":"0b38c6cf-5bf3-423e-8fcf-8c09639de4ab","uri":"https://www.sophos.com/en-us/products/endpoint-antivirus/free-trial","name":"Intercept X Endpoint (Linux)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"86f8c5d8-df9f-4383-bb59-dff4ce54f0d7","sortOrder":4},"sortOrder":4,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"0b38c6cf-5bf3-423e-8fcf-8c09639de4ab"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"0b38c6cf-5bf3-423e-8fcf-8c09639de4ab"}],"recentChangeFlags":null},{"id":"a4d015e9-703d-40fc-aa5a-3ca75e1d82b5","uri":"https://www.sophos.com/en-us/products/mobile-control/free-trial","name":"Intercept X Mobile (iOS)","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3465c1c8-bc62-4f31-81a6-22682e7a1d98","sortOrder":5},"sortOrder":5,"tags":[{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"a4d015e9-703d-40fc-aa5a-3ca75e1d82b5"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"a4d015e9-703d-40fc-aa5a-3ca75e1d82b5"}],"recentChangeFlags":null},{"id":"59bc769e-a37b-44e7-b035-dc0a00a04866","uri":"https://www.sophos.com/en-us/products/mobile-control/free-trial","name":"Intercept X Mobile (Android)","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6681f5b4-16f7-44ef-a490-fddd0b41d8e1","sortOrder":6},"sortOrder":6,"tags":[{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"59bc769e-a37b-44e7-b035-dc0a00a04866"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"59bc769e-a37b-44e7-b035-dc0a00a04866"}],"recentChangeFlags":null},{"id":"205a7314-4c2e-4a06-ac94-67c198c99009","uri":"https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/ThreatAnalysisCenter/Integrations/Sophos/NDR/index.html","name":"Sophos NDR Appliances (NDR, Investigation Console)","category":"iot","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a3b0d643-14cf-46fe-89e9-e5f16212e958","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"1226e256-2e87-4697-ae7b-5023da40bff8","uri":"https://www.sophos.com/en-us/products","name":"Other Sophos Appliances (RED, Switch, Access Points, ...)","category":"iot","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"02df8084-862f-452b-a55a-81ebbec1438a","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null},{"id":"431efb0a-f562-43e9-90cd-a33da1eb7bd1","uri":"https://www.sophos.com/","name":"Sophos-owned IT infrastructure (*.sophos.com)","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b8af0b75-7103-40fa-bbeb-972921d091d4","sortOrder":9},"sortOrder":9,"tags":null,"recentChangeFlags":null},{"id":"f031db01-3aab-4045-a29e-a3fe6817995d","uri":"","name":"SOPHOS/Secureworks : Taegis","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2787de51-ce5a-4404-8136-ef6f57afc6d6","sortOrder":10},"sortOrder":10,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"e82bba17-848b-4f2b-a2a5-58d2a83530d4","name":"Kubernetes","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"f031db01-3aab-4045-a29e-a3fe6817995d"}],"recentChangeFlags":null},{"id":"f2ba335b-e999-43d8-b85d-ba3bc92f24ac","uri":"","name":"SOPHOS/Secureworks : Redcloak","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b0b79903-087e-49d8-bcc0-079c95c126cc","sortOrder":11},"sortOrder":11,"tags":[{"id":"86402f5d-20d0-4c88-92b9-0994786e4241","name":"C++","targetId":"f2ba335b-e999-43d8-b85d-ba3bc92f24ac"},{"id":"ad43847d-d5ec-4d65-a1f1-8f20ec7e9238","name":"Penetration Testing","targetId":"f2ba335b-e999-43d8-b85d-ba3bc92f24ac"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"f2ba335b-e999-43d8-b85d-ba3bc92f24ac"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"9273d723-d6d5-4812-a6a6-35715e43d271","p1MaxCents":800000,"p1MinCents":300000,"p2MaxCents":300000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":30000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eEligible findings are/come with:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReproducible on the latest maintenance release (MR) on an actively maintained product branch that is generally available (GA) \u003c/li\u003e\n\u003cli\u003eDetailed version information \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAll testing can be done with free trial versions of the product on any available platform (software/virtual/hardware/operating system) as applicable. Please refer to our \u003ca href=\"https://docs.sophos.com/releasenotes/index.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003erelease notes\u003c/a\u003e for product updates.\u003c/p\u003e","rewardRangeData":{"1":{"min":3000,"max":8000},"2":{"min":1000,"max":3000},"3":{"min":300,"max":1000},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"aea3b617-c245-44e5-85d8-7e292c70b0de","name":"Bounty Eligible Targets","targets":[{"id":"463a4e32-39a6-403a-9a56-379834cfd8bc","uri":"","name":"3rd party services hosted at *.sophos.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ebd17069-9e92-4a9b-ab88-57fe5824eb6e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"463a4e32-39a6-403a-9a56-379834cfd8bc"}],"recentChangeFlags":null},{"id":"6230d987-cc0a-4bb6-8d8a-76037c1a42d4","uri":"","name":"Sophos IT Infrastructure (all other Sophos domains)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8bed21f7-06a2-4ce5-bd78-fe858561f36c","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"eb8b407c-ebc5-4b5e-9165-d5f84015c95e","uri":"","name":"Any Other Sophos Product or Service","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4d326b86-94ff-4a4e-8d75-5373f359a23c","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"bc338152-2978-46f0-bb4a-9a0e31e54331","p1MaxCents":500000,"p1MinCents":200000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe Sophos \u0026quot;catch-all target\u0026quot; is a way to report any other issue not covered by the Premium or Out of scope targets:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ereceive rewards for P1 findings\u003c/li\u003e\n\u003cli\u003eKudos points for all accepted submissions\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":2000,"max":5000},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f9333dd4-5eb4-4f70-906d-cb4ebdbf80a1","name":"Out of Scope Targets","targets":[{"id":"b0078770-384c-48d8-981c-af1e12096641","uri":"","name":"community.sophos.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6b211eb3-cec4-4959-9e21-7a1596eeb5a8","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"6696d61d-e20d-4526-9a3e-668d07e4f57d","uri":"","name":"Any Cyberoam Product or Service","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"78e92897-fe70-442e-8d74-4230f860c109","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"a142668c-75e0-48d6-9e2e-020f2db4f96c","uri":null,"name":"sophos.atlassian.net (Public service desk)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"dab5ad01-1922-40ca-800b-d6227b5ec5b3","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"f796eef0-c6c4-4841-9447-88855ba7a898","uri":"","name":"SPF/DKIM/DMARC issues","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"28f2fa28-e326-48d2-9f3d-ae532b338e38","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"627b1671-f35d-46b6-830c-72a5183895db","uri":"","name":"Sophos Firewall (Early Access Program (EAP) versions)","category":"iot","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d4e7c3b6-8df8-4229-b475-118922bfcb45","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":5,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"80fb36e8-8d97-476a-b40a-ebac6dfc1ac1","code":"sophos","state":"in_progress","endsAt":null,"bountyId":"caffe1b9-9aba-454a-8687-43eb22f34f5c","startsAt":"2017-12-14T11:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/99ee/d126/b7eb6a5e/3a483054f9f57b3410a4c2fa82d699a0_sophos_ss.jpg","logoBackgroundColor":"#0068b1","displayDisclosureTerms":false,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2017-12-14T11:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/sophos","changelogs":"/engagements/sophos/changelog","submissions":null,"announcements":"/engagements/sophos/announcements","hallOfFame":"/engagements/sophos/hall_of_fames","crowdstream":"/engagements/sophos/crowdstream"},"announcementsCount":26,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/sophos/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=sophos\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/sophos/engagement_subscribers","engagementChangelogsUrl":"/engagements/sophos/changelog","publishedAt":"2025-12-04T10:00:53.560Z","engagementChangelogUrl":"/engagements/sophos/changelog/15ecb6b8-00f6-4b9e-a854-911e5c976a6e","createUserFeedbacksUrl":"/engagements/sophos/feedbacks","engagementCrowdstreamUrl":"/engagements/sophos/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}