{"id":"3b919c1d-a9e6-45cc-a4a8-a98b35a68e0d","engagementId":"ba182074-b4a1-41f9-85c8-4316bfd4034c","data":{"brief":{"id":"8a626584-e264-44df-ab1f-406e12b26b68","name":"Telstra Health VDP","tagline":"Telstra believes it’s people who give purpose to our technology. So we’re committed to staying close to our customers and providing them with the best experience.","description":"\u003cp\u003e\u003cstrong\u003eAbout Telstra Health:\u003c/strong\u003e\u003cbr\u003e\nWelcome to Telstra Health Vulnerability Disclosure Program (VDP). Telstra Health) is subsidiary of Telstra Corporation Limited (“Telstra”). Telstra Health is the largest Australian-based provider of software products, solutions, and platforms for care providers in the hospital, health service, pharmacy, and aged and disability care sectors. Over more than seven years, Telstra Health has grown from a series of distinct acquisitions and start up lines of business to become Australia’s largest eHealth company. \u003c/p\u003e\n\n\u003cp\u003eAt Telstra Health, the security of our systems and customer data is a top priority. We recognize that no technology is flawless, and we highly value the expertise of security researchers worldwide in helping us identify and mitigate potential vulnerabilities. Your contributions play a vital role in strengthening our security posture.\u003cbr\u003e\nAs the program evolves, we will continue to onboard new systems into scope. Stay tuned for updates and announcements on this page\u003cbr\u003e\nThank you for participating in the Telstra Health Vulnerability Disclosure Program (VDP). we look forward to working together to make Telstra’s digital ecosystem more secure.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eEligibility\u003c/strong\u003e\u003cbr\u003e\nNote that the Telstra Health VDP program is in part facilitated through a third party (Bug Crowd) that performs additional services, and eligibility checks on our behalf. For example, Telstra Health may not issue payments if one or more of the following is applicable:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou are a resident of a country under Australian or U.S. sanctions or live in a country that prohibits this type of program.\u003c/li\u003e\n\u003cli\u003eYou are currently (or were in the last 6 months) an employee of Telstra, a Telstra subsidiary, or a third-party contractor with access to Telstra’s internal systems and networks.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eRatings/Rewards:\u003c/strong\u003e\u003cbr\u003e\nFor the initial prioritisation/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eTesting Authorization:\u003c/strong\u003e\u003cbr\u003e\nTesting is only authorised on the targets listed as in scope. Any domain/property of Telstra Health not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Telstra, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003cp\u003eWe cannot authorise testing against these systems.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAccess:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll targets are publicly facing and do not need additional steps to access them.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExcluded Vulnerability Types\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of Service (DoS) or Distributed Denial of Service (DDoS) attacks are not permitted\u003c/li\u003e\n\u003cli\u003eAny attacks which may impact the usability of customer facing services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eCredentials:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis program is set up as an unauthenticated program. The use of personal credentials for testing purposes is strictly prohibited.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOut of Scope:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSocial Engineering and any interaction with Telstra Health physical locations, employees and customers.\u003c/li\u003e\n\u003cli\u003ePlease do not submit forms that may trigger contact with Telstra Health staff, Examples include signing up for products or contacting Telstra Health customer support.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e** Partial Safe Harbour:**\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e","industryTagId":"50214b57-2dde-40fd-ae5a-6680372523d4","targetsOverview":"","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003ch1\u003eSubmission Requirements\u003c/h1\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCategory\u003c/th\u003e\n\u003cth\u003eSpecification\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eCustom Request Header\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: BugCrowd-\u0026lt;username\u0026gt;\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eAutomated Tooling Rate Limit\u003c/td\u003e\n\u003ctd\u003eMaximum of 5 requests per second\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e"},"scope":[{"id":"bbd4c717-3448-4259-95b1-407f5c984940","name":"In-Scope Targets","targets":[{"id":"6dced650-26d4-4988-86c3-b11c5e21362c","uri":"","name":"www.telstrahealth.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"57635cfb-a837-4b94-a616-d883cde10897","sortOrder":0},"sortOrder":0,"tags":[{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"6dced650-26d4-4988-86c3-b11c5e21362c"},{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"6dced650-26d4-4988-86c3-b11c5e21362c"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"6dced650-26d4-4988-86c3-b11c5e21362c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6dced650-26d4-4988-86c3-b11c5e21362c"}],"recentChangeFlags":null},{"id":"56bc1a8b-6cee-4016-aaf5-e3dd72b5cdf6","uri":"","name":"www.ncsr.gov.au","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f5edd824-4035-4b88-adfb-ccd17bd0b6d8","sortOrder":1},"sortOrder":1,"tags":[{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"56bc1a8b-6cee-4016-aaf5-e3dd72b5cdf6"},{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"56bc1a8b-6cee-4016-aaf5-e3dd72b5cdf6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"56bc1a8b-6cee-4016-aaf5-e3dd72b5cdf6"}],"recentChangeFlags":null},{"id":"19d3fca7-3282-4d8b-8ac2-410bb40f750f","uri":"","name":"www.1800respect.org.au","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7399f330-b69d-4c78-9eeb-a7eca88b8751","sortOrder":2},"sortOrder":2,"tags":[{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"19d3fca7-3282-4d8b-8ac2-410bb40f750f"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"19d3fca7-3282-4d8b-8ac2-410bb40f750f"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"19d3fca7-3282-4d8b-8ac2-410bb40f750f"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"19d3fca7-3282-4d8b-8ac2-410bb40f750f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"19d3fca7-3282-4d8b-8ac2-410bb40f750f"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"19d3fca7-3282-4d8b-8ac2-410bb40f750f"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"ba182074-b4a1-41f9-85c8-4316bfd4034c","code":"telstra-health","state":"in_progress","endsAt":null,"bountyId":"bf660b5a-18a7-4cb2-b4b5-fb3b47b955a5","startsAt":"2025-03-11T23:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Healthcare","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/8867/74a9/c69e34c0/8a05adee9561d3d9fa841d5cab2eec60_Negative-mono-RGB.png","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-03-11T23:00:00.365Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/telstra-health","changelogs":"/engagements/telstra-health/changelog","submissions":null,"announcements":"/engagements/telstra-health/announcements","hallOfFame":"/engagements/telstra-health/hall_of_fames","crowdstream":null},"announcementsCount":1,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/telstra-health/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=telstra-health\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/telstra-health/engagement_subscribers","engagementChangelogsUrl":"/engagements/telstra-health/changelog","publishedAt":"2025-10-09T22:35:23.022Z","engagementChangelogUrl":"/engagements/telstra-health/changelog/3b919c1d-a9e6-45cc-a4a8-a98b35a68e0d","createUserFeedbacksUrl":"/engagements/telstra-health/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}