{"id":"74048ca1-6181-43d8-a863-8238914c8ba1","engagementId":"94d8f63c-eeaa-4c14-ad6e-bd52e1abfce1","data":{"brief":{"id":"46819bee-4a65-4057-a6f6-8ddb9a962f04","name":"SpaceX/Starlink","tagline":"Help Secure SpaceX and Starlink!","description":"\u003cp\u003eSpaceX produces rockets, provides launch services, and has developed Starlink - a SpaceX service for providing high speed internet via satellite. SpaceX welcomes researchers to test on their platform in a non-disruptive manner and submit findings as set forth below. SpaceX values the work done by security researchers in improving the security of our products and service offerings. We are committed to working with this community to verify, reproduce and respond to legitimate reported vulnerabilities. We encourage the community to participate in our responsible reporting process. Testing is only authorized on the targets listed as in scope (see the scope page).\u003c/p\u003e\n\n\u003cp\u003eAny domain/property of SpaceX not listed in the targets section is out of scope. This includes any/all subdomains and IPs not listed as in scope. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to SpaceX, you can report it as set forth below. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eStarlink Target Information\u003c/h2\u003e\n\n\u003cp\u003eWhile starlink.com is in scope (see scope section below for more details), we are not currently providing service, credentials, or hardware to researchers. However, researchers are free to test on equipment they own or any in-scope targets that they have access to. \u003c/p\u003e\n\n\u003cp\u003eIf you would like to participate in the Starlink program and purchase hardware, please sign up with a personal email address on starlink.com. Availability is dependent on location and desired class of service.\u003c/p\u003e\n\n\u003cp\u003eWhile we use Bugcrowd as a platform for rewarding all issues, please report issues in satellites, Starlink Dishes, or other hardware directly to vulnerabilityreporting@spacex.com, using our \u003ca href=\"https://www.starlink.com/.well-known/publickey.txt\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGPG key\u003c/a\u003e to encrypt reports containing sensitive information.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eResearching Responsibly\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAs mentioned above, any testing that disrupts service to other users is considered out of scope.\u003c/li\u003e\n\u003cli\u003eAny physical attacks on infrastructure beyond what you physically own is out of scope. More specifically, you are welcome to test on your own Starlink Dish, but physical attacks against any larger scale infrastructure (such as ground stations that affect multiple users) are prohibited.\u003c/li\u003e\n\u003cli\u003eYou are not permitted to chain exploits or perform post-exploitation activities on satellites or other critical infrastructure. If you think you have discovered an issue with a satellite (or are close to discovering one) stop immediately and report the finding.\u003c/li\u003e\n\u003cli\u003eYou are expected to make a good faith disclosure to SpaceX with details of any findings.\u003c/li\u003e\n\u003cli\u003eWe support the open publication of security research. We do ask that you give us a heads-up before any publication so we can do a final sync-up and check.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not engage in any sort of physical attacks on SpaceX/Starlink infrastructure or conduct testing which could interfere with its stability or ability to provide service. If you believe you've found an issue that affects a satellite or other highly sensitive system, please stop and email vulnerabilityreporting@spacex.com — we will work with you to safely complete a proof of concept.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eThird-party bugs\u003c/h2\u003e\n\n\u003cp\u003eIf issues reported to our bug bounty program affect a third-party library, external project, or another vendor, SpaceX reserves the right to forward details of the issue to that third party without further discussion with the researcher. We will do our best to coordinate and communicate with researchers throughout this process. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eResponsible Disclosure Guidelines\u003c/h2\u003e\n\n\u003cp\u003eWe will investigate legitimate reports and make every effort to quickly correct any vulnerability. To encourage responsible reporting, we will not take legal action against you nor ask law enforcement to investigate you provided you comply with the following Responsible Disclosure Guidelines and other rules and guidelines of this program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services.\u003c/li\u003e\n\u003cli\u003eDo not modify or access data that does not belong to you.\u003c/li\u003e\n\u003cli\u003eGive SpaceX a reasonable time to correct the issue before making any information public.\u003c/li\u003e\n\u003cli\u003eDo not abuse vulnerabilities, or exploit them beyond the extent necessary to create a proof-of-concept.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAI-assisted reports\u003c/h2\u003e\n\n\u003cp\u003eWe reserve the right to reject low-quality reports that were clearly AI-generated with little or no human oversight. Good-faith researchers are encouraged to use AI to assist them, but are still responsible for submitting accurate, quality reports, and verifying all findings.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions to the extent that they would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eYou are expected, as always, to comply with all applicable laws. If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRewards\u003c/h2\u003e\n\n\u003cp\u003eWe pay rewards ranging from $100 to $50,000. Rewards are administered according to the following guidelines (see scope tab for target details):\u003c/p\u003e\n\n\u003ch5\u003eWeb/network targets\u003c/h5\u003e\n\n\u003cul\u003e\n\u003cli\u003eRCE: Up to $50,000\u003c/li\u003e\n\u003cli\u003eSQLi: $500–$50,000\u003c/li\u003e\n\u003cli\u003eXSS: $100–$10,000\u003c/li\u003e\n\u003cli\u003eCSRF: $100–$5,000\u003c/li\u003e\n\u003cli\u003eAuthentication bypass: Up to $50,000\u003c/li\u003e\n\u003cli\u003eHorizontal privilege escalation: $500-$10,000\u003c/li\u003e\n\u003cli\u003eVertical privilege escalation: $500–$50,000\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch5\u003eStarlink Dish, satellite, or other products\u003c/h5\u003e\n\n\u003cul\u003e\n\u003cli\u003eCase-by-case, up to $100,000 (report directly, see above). When triaging vulnerabilities, some of the factors we consider are:\n\n\u003cul\u003e\n\u003cli\u003eTarget (Dish, satellite, router, backend infrastructure, etc.)\u003c/li\u003e\n\u003cli\u003eAccess required (physical, local network, authenticated, etc.)\u003c/li\u003e\n\u003cli\u003ePrivileges gained on target\u003c/li\u003e\n\u003cli\u003ePersistence on target\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch1\u003eScope\u003c/h1\u003e\n\n\u003cp\u003eOur targets are separated into two categories: web/network targets and product/infrastructure targets. These pay differently, as listed on the program details page.\u003c/p\u003e\n\n\u003ch3\u003eIn-scope web/network targets\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e*.spacex.com, \u003cstrong\u003eexcept for shop.spacex.com\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003e*.starlink.com, \u003cstrong\u003eexcept for gear.starlink.com or customer.*.isp.starlink.com - see below for a full list of excluded IPs\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003eOfficial Starlink \u003ca href=\"https://apps.apple.com/us/app/starlink/id1537177988\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eiOS\u003c/a\u003e and \u003ca href=\"https://play.google.com/store/apps/details?id=com.starlink.mobile\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAndroid\u003c/a\u003e apps\u003c/li\u003e\n\u003cli\u003e4.7.106.0/28\u003c/li\u003e\n\u003cli\u003e4.34.86.130/31\u003c/li\u003e\n\u003cli\u003e4.34.86.132/31\u003c/li\u003e\n\u003cli\u003e4.34.86.134/32\u003c/li\u003e\n\u003cli\u003e63.208.93.16/29\u003c/li\u003e\n\u003cli\u003e66.9.191.192/28\u003c/li\u003e\n\u003cli\u003e135.129.252.112/31\u003c/li\u003e\n\u003cli\u003e135.129.254.0/24\u003c/li\u003e\n\u003cli\u003e164.152.165.0/24\u003c/li\u003e\n\u003cli\u003e192.31.242.0/23\u003c/li\u003e\n\u003cli\u003e199.175.188.0/24\u003c/li\u003e\n\u003cli\u003e206.214.224.139/32\u003c/li\u003e\n\u003cli\u003e206.214.224.233/32\u003c/li\u003e\n\u003cli\u003e206.214.229.128/27\u003c/li\u003e\n\u003cli\u003e206.214.229.4/30\u003c/li\u003e\n\u003cli\u003e206.214.239.8/30\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eexcept for the following IPs and IP ranges:\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003e66.9.188.0/24\u003c/li\u003e\n\u003cli\u003e66.9.189.0/24\u003c/li\u003e\n\u003cli\u003e66.9.190.0/24\u003c/li\u003e\n\u003cli\u003e74.245.192.0/19\u003c/li\u003e\n\u003cli\u003e75.78.128.0/17\u003c/li\u003e\n\u003cli\u003e179.65.224.0/21\u003c/li\u003e\n\u003cli\u003e192.31.242.107\u003c/li\u003e\n\u003cli\u003e192.31.242.108\u003c/li\u003e\n\u003cli\u003e192.31.242.109\u003c/li\u003e\n\u003cli\u003e192.31.242.111\u003c/li\u003e\n\u003cli\u003e192.31.242.112\u003c/li\u003e\n\u003cli\u003e192.31.242.113\u003c/li\u003e\n\u003cli\u003e192.31.242.115\u003c/li\u003e\n\u003cli\u003e192.31.242.116\u003c/li\u003e\n\u003cli\u003e192.31.242.120\u003c/li\u003e\n\u003cli\u003e206.214.228.0/22\u003c/li\u003e\n\u003cli\u003e216.255.176.0/20\u003c/li\u003e\n\u003cli\u003e2605:59c7:9000::/36\u003c/li\u003e\n\u003cli\u003e2606:ee40:4000::/34\u003c/li\u003e\n\u003cli\u003e2606:ee40:8000::/35\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eIn-scope product/infrastructure targets\u003c/h3\u003e\n\n\u003cp\u003eReminder: reports for these targets should be sent directly to vulnerabilityreporting@spacex.com, and encrypted with our \u003ca href=\"https://www.starlink.com/.well-known/publickey.txt\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGPG key\u003c/a\u003e if needed.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eHardware that you own or are authorized to test against (Starlink Dish/Router)\u003c/li\u003e\n\u003cli\u003e*.starlinkisp.net, excluding customer.*.pop.starlinkisp.net (PLEASE NOTE THE EXCLUSION. Some services may be considered web targets, especially those which provide information only, such as dashboards)\n\n\u003cul\u003e\n\u003cli\u003e2620:134:b000::/40\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut of scope targets\u003c/h3\u003e\n\n\u003cp\u003eNote: If reports are submitted for out of scope targets, including targets below or anything not explicitly in-scope above, SpaceX reserves the right to forward the full report (including reporter contact information, if given in the report body) to relevant third-parties at its discretion.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny customer IP listed \u003ca href=\"https://geoip.starlinkisp.net/feed.csv\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e, excluding those explicitly as in-scope.\u003c/li\u003e\n\u003cli\u003ecustomer.*.pop.starlinkisp.net or customer.*.isp.starlink.com (for example, customer.sttlwax1.pop.starlinkisp.net or customer.tmpeazx1.isp.starlink.com), excluding those explicitly as in-scope.\u003c/li\u003e\n\u003cli\u003eshop.spacex.com\u003c/li\u003e\n\u003cli\u003egear.starlink.com\u003c/li\u003e\n\u003cli\u003e66.9.188.0/24\u003c/li\u003e\n\u003cli\u003e66.9.189.0/24\u003c/li\u003e\n\u003cli\u003e66.9.190.0/24\u003c/li\u003e\n\u003cli\u003e74.245.192.0/19\u003c/li\u003e\n\u003cli\u003e75.78.128.0/17\u003c/li\u003e\n\u003cli\u003e179.65.224.0/21\u003c/li\u003e\n\u003cli\u003e192.31.242.107\u003c/li\u003e\n\u003cli\u003e192.31.242.108\u003c/li\u003e\n\u003cli\u003e192.31.242.109\u003c/li\u003e\n\u003cli\u003e192.31.242.111\u003c/li\u003e\n\u003cli\u003e192.31.242.112\u003c/li\u003e\n\u003cli\u003e192.31.242.113\u003c/li\u003e\n\u003cli\u003e192.31.242.115\u003c/li\u003e\n\u003cli\u003e192.31.242.116\u003c/li\u003e\n\u003cli\u003e192.31.242.120\u003c/li\u003e\n\u003cli\u003e206.214.228.0/22\u003c/li\u003e\n\u003cli\u003e216.255.176.0/20\u003c/li\u003e\n\u003cli\u003e2605:59c7:9000::/36\u003c/li\u003e\n\u003cli\u003e2606:ee40:4000::/34\u003c/li\u003e\n\u003cli\u003e2606:ee40:8000::/35\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eThe following finding types are specifically out of scope:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eLack of MFA\u003c/li\u003e\n\u003cli\u003eOpen redirects (through headers and parameters) / Lack of security speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure.\u003c/li\u003e\n\u003cli\u003eAccessible Non-sensitive files and directories (e.g. README.TXT, CHANGES.TXT, robots.txt, .gitignore, etc).\u003c/li\u003e\n\u003cli\u003eSocial engineering / phishing attacks.\u003c/li\u003e\n\u003cli\u003eSelf XSS.\u003c/li\u003e\n\u003cli\u003eWeb app \"environment.js\" file exposure - this file and the variables within are intentionally public.\u003c/li\u003e\n\u003cli\u003eText injection.\u003c/li\u003e\n\u003cli\u003eEmail spoofing (including SPF, DKIM, DMARC, From: spoofing, and visually similar, and related issues).\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. stack traces, application or server errors, path disclosure).\u003c/li\u003e\n\u003cli\u003eFingerprinting/banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF issues that don't impact the integrity of an account (e.g. log in or out, contact forms and other publicly accessible forms)\u003c/li\u003e\n\u003cli\u003eLack of Secure and HTTPOnly cookie flags (critical systems may still be in scope).\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force, account lockout not enforced, or insufficient password strength requirements\u003c/li\u003e\n\u003cli\u003eLack of rate limiting or other missing DOS protections.\u003c/li\u003e\n\u003cli\u003eHTTPS mixed content scripts.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration by brute forcing / error messages (e.g. login / signup / forgotten password).\n\n\u003cul\u003e\n\u003cli\u003eExceptional cases may still be in scope (e.g. ability to enumerate email addresses via incrementing a numeric parameter).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers.\u003c/li\u003e\n\u003cli\u003eTLS/SSL Issues, including BEAST, BREACH, insecure renegotiation, bad cipher suite, expired certificates, etc.\n\n\u003cul\u003e\n\u003cli\u003eCases which affect Starlink hardware (such as user data encryption in the Starlink Dish) may be in scope.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eStandard WPA cracking attacks, such as those that result from users choosing weak passwords.\u003c/li\u003e\n\u003cli\u003ephpinfo() info leaks (exceptional cases, such as where you are able to leak sensitive credential information, may still be in scope)\u003c/li\u003e\n\u003cli\u003eDenial of Service attacks.\u003c/li\u003e\n\u003cli\u003eOut-of-date software.\u003c/li\u003e\n\u003cli\u003eUse of a known-vulnerable component (exceptional cases, such as where you are able to provide proof of exploitation, may still be in scope).\u003c/li\u003e\n\u003cli\u003ePhysical attacks against SpaceX's Facilities/Property.\u003c/li\u003e\n\u003cli\u003eLeaked customer credentials due to client-side issues out of SpaceX's control (e.g. client side malware, credential stuffing, web archive links that could be self-archived, etc.)\u003c/li\u003e\n\u003cli\u003e\"Confidential\" or \"Proprietary\" files on the Internet without demonstrated security impact. We're not interested in theoretical information leaks.\u003c/li\u003e\n\u003cli\u003eCORS issues without demonstrated security impact.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":null,"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"fbaac262-0d9b-4a82-b9e3-8bf89dbe8d8f","name":"In Scope targets","targets":[{"id":"b191a0e3-d0ed-47f9-9221-519132bfe00d","uri":"","name":"SpaceX and Starlink assets (target information and rewards detailed above on the brief)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6d8a57c5-1979-4c19-902d-e980117fe518","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"f3788644-aed0-4c46-8be8-c37f4f1c210f","p1MaxCents":10000000,"p1MinCents":null,"p2MaxCents":5000000,"p2MinCents":null,"p3MaxCents":1000000,"p3MinCents":null,"p4MaxCents":100000,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":0,"max":100000},"2":{"min":0,"max":50000},"3":{"min":0,"max":10000},"4":{"min":0,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"94d8f63c-eeaa-4c14-ad6e-bd52e1abfce1","code":"spacex","state":"in_progress","endsAt":null,"bountyId":"d5aecba2-846f-4afc-afc9-5cd7b6463ce9","startsAt":"2020-10-22T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2a86/e629/8bcbecde/0c6ceca416865abd3e7e16067c012149_spacex.jpg","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-10-22T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/spacex","changelogs":"/engagements/spacex/changelog","submissions":null,"announcements":"/engagements/spacex/announcements","hallOfFame":"/engagements/spacex/hall_of_fames","crowdstream":"/engagements/spacex/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Self-managed","submitReportUrl":"/engagements/spacex/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=spacex\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/spacex/engagement_subscribers","engagementChangelogsUrl":"/engagements/spacex/changelog","publishedAt":"2026-08-31T23:58:39.380Z","engagementChangelogUrl":"/engagements/spacex/changelog/74048ca1-6181-43d8-a863-8238914c8ba1","createUserFeedbacksUrl":"/engagements/spacex/feedbacks","engagementCrowdstreamUrl":"/engagements/spacex/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}