{"id":"0ec956e3-5e7d-4f54-9369-1991ba69bfb5","engagementId":"5fa4fa1b-36ac-45f3-81aa-f2f6f2349bbe","data":{"brief":{"id":"7acc109d-c801-4973-9ebf-c7c49fabbce6","name":"Cisco ThousandEyes Vulnerability Disclosure Program (VDP)","tagline":"ThousandEyes enables organizations to see and take action to maintain and optimize every digital journey that matters. ","description":"\u003cp\u003eCisco ThousandEyes enables organizations to see and take action to maintain and optimize every digital journey that matters. From application experience to hop-by-hop network path and performance, Cisco ThousandEyes provides end-to-end visibility from every user to any application over any network. Now, you can maximize the value of your digital investments and leverage them to drive differentiation in the market.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eNo technology is perfect, and ThousandEyes believes that working with skilled security researchers worldwide is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher and help us identify vulnerabilities in our targets. Good luck, and happy hunting!\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eAny domain/property of ThousandEyes not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccessing the offerings:\u003c/h2\u003e\n\n\u003cp\u003eTo register for an account, please go \u003ca href=\"https://www.thousandeyes.com/signup\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease sign up for an account using your @bugcrowdninja.com email address (see here for more info regarding @bugcrowdninja.com emails \u003ca href=\"https://researcherdocs.bugcrowd.com/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://researcherdocs.bugcrowd.com/docs/your-bugcrowdninja-email-address\u003c/a\u003e). \u003cstrong\u003eIf you don't use your @bugcrowdninja address, your account will not be accepted, and you may be IP banned if you proceed to test\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003eUse Bugcrowd for the First, Last, and Company name fields.\u003c/li\u003e\n\u003cli\u003eThis will forward a request to our team, and your account will be activated within one business day.\u003c/li\u003e\n\u003cli\u003eA new organization will be created for you, and the account used to sign up will permit you to be an Organization Admin. You can also make other users with lower-level privileges - researchers are encouraged to create other users to test vertical privilege escalation issues, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eUseful links(Documentation):\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAPI Documentation*: \u003ca href=\"https://developer.thousandeyes.com/v6/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eDeveloper Documentation*: \u003ca href=\"http://developer.thousandeyes.com/v6/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eGetting Started with ThousandEyes*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnbKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eRole-Based Access Control*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnLKAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAgent Types*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA044000000CnvICAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWhat is an Enterprise Agent? Working with Agent settings*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnbKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eFirewall configuration for Enterprise agents*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA044000000CnBtCAK\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eGetting started with Endpoint Agent*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmpZKAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eHow to set up the Virtual appliance*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnwKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with the dashboard*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmmdKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with Test settings*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000Cmn7KAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with Alerts*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA044000000CnBqCAK_How-Alerts-work\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with Reports*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnTKAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAny other useful links can be accessed by searching on this page*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFocus Areas:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eIDOR (Insecure Direct Object Reference)\u003c/li\u003e\n\u003cli\u003eAuthentication Bypass\u003c/li\u003e\n\u003cli\u003eAuthentication Related Issues\u003c/li\u003e\n\u003cli\u003eLocal Privilege Escalation\u003c/li\u003e\n\u003cli\u003eCross-Account Access\u003c/li\u003e\n\u003cli\u003eIncorrect Permissions\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003eRemote Code Execution\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eCommand Injection\u003c/li\u003e\n\u003cli\u003eLocal File Inclusion\u003c/li\u003e\n\u003cli\u003eRemote File Inclusion\u003c/li\u003e\n\u003cli\u003eDirectory Traversal\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eOWASP Top 10\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope Submissions:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eLeaked credentials from 3rd parties\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis includes credential dumps found on websites, leaked credentials from indirect sources other than ThousandEyes, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope Activities:\u003c/h2\u003e\n\n\u003cp\u003eThis program is designed to review and address security issues related to Cisco ThousandEyes. Please note that anything not explicitly listed as in-scope is considered out-of-scope.  \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eYou must not exploit, investigate, or target vulnerabilities against vendors used by ThousandEyes to provide the ThousandEyes offering, for example, you must not exploit, investigate, or target vulnerabilities against Amazon Web Services’ infrastructure.  \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you believe you have found a vulnerability that is outside of this program's scope but related to Cisco, please refer to the resources below: \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you need to report a vulnerability in a Cisco product, please contact psirt@cisco.com. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you need to contact Cisco regarding a security incident, please contact incidentresponse@cisco.com. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCisco Systems Operational Infrastructure findings can be reported here: https://bugcrowd.com/ciscosecurity\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eFurther information can be found here: https://www.cisco.com/security \u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eManual crafting/ manual generation of malicious Agent traffic\u003c/strong\u003e    Do NOT attempt to send manually crafted or altered Agent traffic to the ThousandEyes application. Vulnerabilities that occur through test settings configured in the ThousandEyes web application \u003cem\u003eare valid vectors for attack\u003c/em\u003e. Vulnerabilities that involve manually (‘manual’ includes tools like Burp Intruder, ZAP, python scripts, etc.) sending traffic to the Agent data ingress points or controllers (c1.thousandeyes.com, eb.thousandeyes.com, etc.) \u003cem\u003eare not valid vectors for attack\u003c/em\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eEdited binaries do not qualify as valid findings\u003c/strong\u003e    If a vulnerability relies on the generation or use of a binary created by someone other than ThousandEyes, it will not be considered for this campaign.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRegistration of Agents into Other Accounts\u003c/strong\u003e    Do not register Enterprise or Endpoint Agents into other ThousandEyes user accounts. Do not report the registration of an Agent into another account as a vulnerability.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eProhibited Tools and Methods.\u003c/strong\u003e  Do not use any tools or methods that have the potential to automatically generate volumes of traffic that may be considered a Denial of Service (DoS) event or in any way may impact our delivery of products and services.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDestroying Data and Interference with Services and Systems.\u003c/strong\u003e  Do not destroy data or interruption or degradation related, either directly or indirectly, to our services and systems.  Your research must be performed to view, capture, change, divert, or otherwise compromise any data that is not yours.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNo Data Access Permitted.\u003c/strong\u003e  \u003cstrong\u003eYou are not permitted to intentionally view, capture, change, disclose, retain, or otherwise interact with any data, including ThousandEyes data or ThousandEyes’s customer data, that is not directly related to a Vulnerability subject to this Program. If you discover a Vulnerability that allows you to access the data of anyone else, including any ThousandEyes data or ThousandEyes’s customer data, immediately cease accessing such data upon detection of such Vulnerability and promptly notify ThousandEyes so we can promptly secure that data. See the Legal Information below.\u003c/strong\u003e   \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePersonal Data Access Prohibited.\u003c/strong\u003e  You are not permitted to intentionally view, capture, change, disclose, control, process, or otherwise interact with any Personal Data concerning this Program. “Personal Data” means any information relating to an identifiable individual (also called Personally Identifiable Data). If you gain access to Personal Data, please immediately cease the activities giving rise to that access and promptly notify ThousandEyes so we can promptly secure that data. Do not identify names of individuals or ThousandEyes customers in your Reports. Do not include unnecessary information in your submission to investigate your Reports.  \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAccessing other Accounts Prohibited.\u003c/strong\u003e\u003cbr\u003e\u003cbr\u003e\n\u003cstrong\u003eWhen investigating a Vulnerability, please only target your account. Never intentionally attempt to access anyone else's data, and do not engage in any activity that would damage ThousandEyes, its customers, partner community, employees, or others.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAutomated Vulnerability Scanning.\u003c/strong\u003e\u003cbr\u003e\n\u003cstrong\u003ePlease note that using automated vulnerability scanning tools like Nuclei or Nessus is strictly prohibited in our program.  Additionally, Turbo Intruder is permitted ONLY to test unique functionality that only Turbo Intruder can find. Ensure you are only limiting this to 15 requests. If there's abuse, you will be removed from the program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003eKnown Issues, ThousandEyes Web Application:\u003c/h3\u003e\n\n\u003cp\u003e30 May 2024\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser-defined hyperlinks can be inserted into signup welcome emails. This has been assessed as a Low-Risk issue.\u003c/li\u003e\n\u003cli\u003eAPI Access for documentation account (e.g., one can use the credentials provided in the official documentation to perform authenticated API requests)\u003c/li\u003e\n\u003cli\u003eLack of ‘adequate’ Content Security Policy on all domains\u003c/li\u003e\n\u003cli\u003eThere is a lack of sufficient Automation Protection on the Forgot Password form (e.g., the form can be used to send spam).\u003c/li\u003e\n\u003cli\u003eOverly permissive CORS Policy (on all domains)\u003c/li\u003e\n\u003cli\u003eAccount lockout logic - e.g., one can successfully enumerate valid account IDs via the lockout feature.\u003c/li\u003e\n\u003cli\u003eThe user ID is displayed in cookies Cookies and Request Headers\u003c/li\u003e\n\u003cli\u003eMultiple concurrent sessions allowed\u003c/li\u003e\n\u003cli\u003eLack of maximum session length for any application interface (or ‘Agent’ interface)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eKnown Issues, ThousandEyes Enterprise Agent:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny package-based vulnerabilities in the downloadable ‘Enterprise Agent’ images that are not sourced from or directly imposed by the ThousandEyes ‘Agent’ software (this includes all operating system patches and CIS hardening controls)\u003c/li\u003e\n\u003cli\u003eCertain ‘Agent’ interfaces may report a lack of clickjacking defense\u003c/li\u003e\n\u003cli\u003eHTTPS is not strictly enforced on Enterprise Agents\u003c/li\u003e\n\u003cli\u003eThe HTTPS web app on the appliance site lacks Strict Transport Security\u003c/li\u003e\n\u003cli\u003eSession Cookie not set with ‘Secure’ flag in the ‘Admin’ interface of the Virtual Appliance\u003c/li\u003e\n\u003cli\u003eAgents do not require approval to register to the ThousandEyes platform\u003c/li\u003e\n\u003cli\u003eAppliance-based ‘Agents’ contain known SSH CVEs labeled as ‘no-patch,’ i.e., “Will Not Fix” by Canonical\u003c/li\u003e\n\u003cli\u003eSelf-signed HTTPS hosts are by design. Customers can upgrade certs as required\u003c/li\u003e\n\u003cli\u003eA lack of ‘SECCOMP’ or similar controls for hardening container-based agent activities\u003c/li\u003e\n\u003cli\u003eCIS compliance violations of any ‘Agent’ type are treated as ‘known’ (not in scope)\u003c/li\u003e\n\u003cli\u003eAny ‘binary analysis’ (e.g., detection of allegedly vulnerable versions in raw strings) based findings on any downloadable ‘Agent’ artifact are not in scope\u003c/li\u003e\n\u003cli\u003eA lack of ‘required password complexity’ for the administrative HTTPS user\u003c/li\u003e\n\u003cli\u003eThe default user/pass combination for the ‘Agent’ HTTPS interface is not strong enough\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eKnown Issues, ThousandEyes Endpoint Agents:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny ‘CVE’ based detections that appear to be disclosed by ‘binary analysis,’ or related processes (not in scope)\u003c/li\u003e\n\u003cli\u003eAny ‘compile-time’ detections, including ‘security build-time options’ for any ThousandEyes installer or executable, are not in scope\u003c/li\u003e\n\u003cli\u003eThe ‘Endpoint Agent’ runs as SYSTEM on Windows operating systems\u003c/li\u003e\n\u003cli\u003eThe ‘Endpoint Agent’ is built uniquely per customer endpoint by the ThousandEyes application; as such, any identifying characteristics based on hashing or similar measures are not in scope\u003c/li\u003e\n\u003cli\u003eAny findings that are related to associated libraries being executed ‘only in secured environments’ are not considered to be in scope\u003c/li\u003e\n\u003cli\u003eDetections based on ‘certificates’ or ‘signatures’ regardless of the certificate authority or operating system provider are not considered to be in scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLegal Information\u003c/h2\u003e\n\n\u003cp\u003eIn addition to these Terms and Conditions regarding the Cisco ThousandEyes Program, there may be additional restrictions depending upon applicable local laws. \u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e\u003cp\u003eThe parties to this Agreement are you and ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\"ThousandEyes\" refers to ThousandEyes LLC. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBy participating in the Program, investigating a potential vulnerability, or submitting a vulnerability, you affirm that you have not disclosed and agree that you will not disclose the vulnerability to anyone other than ThousandEyes. Absent ThousandEyes 's prior written consent, any disclosure outside of this process would violate this Agreement. You agree that money damages may not be a sufficient remedy for a breach of this paragraph by you and that ThousandEyes will be entitled to specific performance as a remedy for any such breach. Such remedy will not be deemed to be the exclusive remedy for any such breach but will be in addition to all other remedies available at law or equity to ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBy submitting information about a potential vulnerability, you are granting ThousandEyes a worldwide, royalty-free, non-exclusive license to use your submission for the purpose of addressing vulnerabilities in ThousandEyes’ products and services. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIn the event of substantially duplicate submissions, ThousandEyes may at its discretion provide a reward only for the earliest received submission. Eligibility for rewards, determination of the recipients, and amount of reward is at the discretion of ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf issues reported to our bug bounty program affect a third party or another vendor, ThousandEyes reserves the right to forward details of the issue along to the party without further discussion with the researcher. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou are responsible for all taxes associated with and imposed on any reward you may receive from ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou may only exploit, investigate, or target vulnerabilities against your own accounts and/or your own devices. Testing must not violate any law, or disrupt or compromise any data or access data that is not yours; intentional access of customer data other than your own is prohibited. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you inadvertently access proprietary customer, employee, or business related information during your testing, the information must not be used, disclosed, stored, or recorded in any way. In the event of inadvertent access to such data, you must delete such data immediately and notify ThousandEyes of such inadvertent access within your submission. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYour testing activities must not negatively impact ThousandEyes, ThousandEyes’ products or services generally, or ThousandEyes’ online environment availability or performance. ThousandEyes may choose not to remediate at its sole discretion. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThis Agreement constitutes the entire agreement of the parties with respect to the items listed above. This Agreement is covered by California law. This Agreement may be amended or modified only by a subsequent agreement in writing. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf any portion of this Agreement is found to be illegal or unenforceable, then the parties will be relieved of their responsibilities arising under such portion, but only to the extent that such portion is illegal or unenforceable. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must not be the author of the code with the vulnerability. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must not be an employee or contractor of ThousandEyes or its affiliates, or a family member of an employee or contractor. \u003c/p\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eTHOUSANDEYES RESERVES THE RIGHT TO MODIFY OR CANCEL THIS PROGRAM AT ANY TIME WITHOUT NOTICE. ALL PARTICIPANTS AND SUBMISSIONS ARE STRICTLY VOLUNTARY. THIS OFFER IS VOID WHERE PROHIBITED BY LAW AND IN PARTICIPATING, YOU MUST NOT VIOLATE ANY LAW. YOU ALSO MUST NOT DISRUPT ANY SERVICE OR COMPROMISE ANYONE’S DATA. \u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1ff87949-dd90-432a-8366-9e738d5d7ff2","name":"ThousandEyes Enterprise Agent","targets":[{"id":"949bd7d3-ed7b-4d82-bcbe-abbb26e579e1","uri":"https://app.thousandeyes.com/","name":"https://app.thousandeyes.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0a1a4fa8-5a2d-401d-8e0b-520dc8556d7b","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"949bd7d3-ed7b-4d82-bcbe-abbb26e579e1"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"949bd7d3-ed7b-4d82-bcbe-abbb26e579e1"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"949bd7d3-ed7b-4d82-bcbe-abbb26e579e1"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"949bd7d3-ed7b-4d82-bcbe-abbb26e579e1"}],"recentChangeFlags":null},{"id":"353c4ced-9ade-4495-b472-a18402f4a081","uri":"https://www.thousandeyes.com/","name":"https://www.thousandeyes.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"820b996d-a70b-44ff-96e2-eb83122474e1","sortOrder":0},"sortOrder":0,"tags":[{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"353c4ced-9ade-4495-b472-a18402f4a081"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"353c4ced-9ade-4495-b472-a18402f4a081"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"353c4ced-9ade-4495-b472-a18402f4a081"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"353c4ced-9ade-4495-b472-a18402f4a081"}],"recentChangeFlags":null},{"id":"837c3a0a-846b-4708-89c5-646ef38f55c6","uri":"","name":"https://api.thousandeyes.com/","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b54703a7-97f3-4176-8b7f-365083cca1ce","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"837c3a0a-846b-4708-89c5-646ef38f55c6"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"837c3a0a-846b-4708-89c5-646ef38f55c6"}],"recentChangeFlags":null},{"id":"0e8acf9e-326f-4e85-911c-fa1997313b86","uri":"","name":"ThousandEyes Enterprise Agent","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d6e9a1d5-0a95-4ac8-8e2c-95e4f4a56187","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"0e8acf9e-326f-4e85-911c-fa1997313b86"}],"recentChangeFlags":null},{"id":"c2b3e894-e519-438b-87ef-07d4e5c73b15","uri":"","name":"ThousandEyes Endpoint Agent ","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1ab0e8d3-4ad3-40e2-a473-b9d0925c5eba","sortOrder":0},"sortOrder":0,"tags":[{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"c2b3e894-e519-438b-87ef-07d4e5c73b15"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch1\u003eTarget Information:\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://app.thousandeyes.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eapp.thousandeyes.com\u003c/a\u003e\u003c/strong\u003e—This is our web application platform, a core component of ThousandEyes SaaS that Customers use to create network performance monitoring tests, alerts, and reports.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://www.thousandeyes.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ewww.thousandeyes.com\u003c/a\u003e\u003c/strong\u003e—This is our company website. It provides information about our services, allows new users to create accounts, and directs existing users to the web application platform.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eapi.thousandeyes.com\u003c/strong\u003e—This is our customer-accessible API. It allows programmatic interaction with the web application platform.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eThousandEyes Enterprise Agent (Linux)\u003c/strong\u003e - The ThousandEyes platform uses agents to run tests against targets configured for measurement. An agent is a Linux server running custom ThousandEyes software, which checks in with an agent collector to obtain instructions from the ThousandEyes platform. \u003ca href=\"https://docs.thousandeyes.com/product-documentation/global-vantage-points/enterprise-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMore information\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eThousandEyes Endpoint Agent (Windows)\u003c/strong\u003e - The ThousandEyes Endpoint Agent is an application installed on user endpoint machines to collect network- and application-layer performance data when users access specific websites from monitored networks. \u003ca href=\"https://docs.thousandeyes.com/product-documentation/global-vantage-points/endpoint-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMore information\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOther than the above, everything else is considered out of scope. Additional details on what is out of scope are below on this page.\u003c/strong\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"5fa4fa1b-36ac-45f3-81aa-f2f6f2349bbe","code":"thousandeyes-vdp","state":"in_progress","endsAt":null,"bountyId":"ed9864ef-54f9-410c-b4e5-2b0f5533b59f","startsAt":"2024-05-28T00:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2b29/0d1f/5dcd49cf/4a7dab456e139dacc5abbff4c4fb7d6c_Cisco_ThousandEyes_Logo_Stacked_Orange_Blue.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-05-28T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/thousandeyes-vdp","changelogs":"/engagements/thousandeyes-vdp/changelog","submissions":null,"announcements":"/engagements/thousandeyes-vdp/announcements","hallOfFame":"/engagements/thousandeyes-vdp/hall_of_fames","crowdstream":"/engagements/thousandeyes-vdp/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/thousandeyes-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=thousandeyes-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/thousandeyes-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/thousandeyes-vdp/changelog","publishedAt":"2024-11-18T21:32:47.180Z","engagementChangelogUrl":"/engagements/thousandeyes-vdp/changelog/0ec956e3-5e7d-4f54-9369-1991ba69bfb5","createUserFeedbacksUrl":"/engagements/thousandeyes-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/thousandeyes-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}