{"id":"cab773d9-01e1-40cb-932b-7c5a4f2829fd","engagementId":"36bc7b3a-ba7a-4f94-b2f5-29d329a28a55","data":{"brief":{"id":"d7ce61c3-b12c-4a67-824b-cf65dfccc625","name":"Verisign Bug Bounty","tagline":"A global provider of critical internet infrastructure and domain name registry services.","description":"\u003cp\u003eVerisign’s critical yet mostly invisible role – helping to maintain the security, stability and resiliency of the Domain Name System (DNS) and the internet – can sometimes be overshadowed by more visible aspects of the domain name business. The importance of what we do behind the scenes, however, helps the world connect online every day.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect, and Verisign believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Verisign's not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you believe you've identified a vulnerability on a target that is not in scope, but it demonstrably belongs to Verisign, please reach out to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before submitting.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEligible Vulnerabilities within the Targets\u003c/h2\u003e\n\n\n\u003cul\u003e\n\u003cli\u003eCross-site scripting \u003c/li\u003e\n\u003cli\u003eCross-site request forgery \u003c/li\u003e\n\u003cli\u003eAuthentication or authorization flaws \u003c/li\u003e\n\u003cli\u003eServer-side code execution bugs \u003c/li\u003e\n\u003cli\u003eDNS vulnerabilities \u003c/li\u003e\n\u003cli\u003eWHOIS vulnerabilities \u003c/li\u003e\n\u003cli\u003eLocal file includes \u003c/li\u003e\n\u003cli\u003eXML external entity processing \u003c/li\u003e\n\u003cli\u003eServer-side request forgery\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Targets\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny Verisign services or systems not specifically listed as an in-scope Target above. \u003c/li\u003e\n\u003cli\u003eAny third-party apps, servers, or websites that integrate with Verisign. These are not managed by Verisign and do not qualify under our guidelines for security testing. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExcluded Vulnerability Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of service attacks \u003c/li\u003e\n\u003cli\u003eUsername / email enumeration by brute forcing / error messages (e.g. login / signup/ forgotten password)\n\n\u003cul\u003e\n\u003cli\u003eExceptional cases may still be in scope (e.g. ability to enumerate email addresses via incrementing anumeric parameter) \u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSpamming/social engineering/phishing attacks\n\n\u003cul\u003e\n\u003cli\u003eIncludes email spoofing Email spoofing (including SPF, DKIM, From: spoofing, and visually similar, and related issues) \u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eOpen redirects (through headers and parameters)\u003c/li\u003e\n\u003cli\u003eLack of security speedbump when leaving the site \u003c/li\u003e\n\u003cli\u003eAccessible Non-sensitive files and directories (e.g. README.TXT, CHANGES.TXT, robots.txt, gitignore, etc.) \u003c/li\u003e\n\u003cli\u003eFingerprinting/banner disclosure on common/public services \u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking \u003c/li\u003e\n\u003cli\u003eLack of Secure and HTTPOnly cookie flags (critical systems may still be in scope) \u003c/li\u003e\n\u003cli\u003eTLS/SSL Issues, including BEAST BREACH, insecure renegotiation, bad cipher suite, expired certificates\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eVerisign Responsible Disclosure Program Terms\u003c/h2\u003e\n\n\u003cp\u003eWe appreciate security researchers who help us keep Verisign employees and systems secure by reporting vulnerabilities in our services or infrastructure. Researchers who report such vulnerabilities may receive monetary bounties subject to the terms and conditions outlined below. To qualify for a bounty, researchers must meet the following requirements:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must adhere to our Responsible Disclosure Policy (see below). \u003c/li\u003e\n\u003cli\u003eYour report must address one of the in-scope Targets and must identify an eligible vulnerability (see above).\u003c/li\u003e\n\u003cli\u003eWe specifically exclude certain targets as out-of-scope and certain security issues as ineligible (see above). \u003c/li\u003e\n\u003cli\u003eYou should provide sufficient proof of the vulnerability, such as a written description of the vulnerability or a screenshot demonstrating its existence. \u003c/li\u003e\n\u003cli\u003eYou agree to convey any and all intellectual property rights arising from or relating to each vulnerability you provide under Verisign's Program Brief. \u003c/li\u003e\n\u003cli\u003eIf you inadvertently access account data, service configurations, or other confidential information (collectively “Data\") while investigating an issue, you are prohibited from saving, storing, transferring or otherwise further accessing any and all such Data after discovery.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eIn turn, we follow these guidelines when evaluating reports under our bug bounty program:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe investigate all reports and respond to all reports relating to in-scope targets and eligible vulnerabilities. Due to the volume of reports we receive, we prioritize evaluations based on risk and other factors, and it may take some time before you receive a reply. \u003c/li\u003e\n\u003cli\u003eWe determine bounty amounts based on a variety of factors, including (but not limited to) impact, ease of exploitation, and quality of the report. You can find further information in our Rewards Guidelines below. \u003c/li\u003e\n\u003cli\u003eWe generally pay similar amounts for similar issues, but bounty amounts and qualifying issues may change over time. Past rewards do not necessarily guarantee similar results in the future. \u003c/li\u003e\n\u003cli\u003eIn the event of duplicate reports addressing the same vulnerability, we award a bounty to the first person to report an issue with sufficient proof.\u003c/li\u003e\n\u003cli\u003eWe reserve the right to publish reports (and accompanying updates). \u003c/li\u003e\n\u003cli\u003eWe may post a list of researchers who have submitted valid security reports. If you receive a bounty for discovery of a vulnerability, you are eligible to be included in this list, but you may opt not to be included if you wish. We reserve the right to limit or modify the information accompanying your name in the list. \u003c/li\u003e\n\u003cli\u003e[Bugcrowd] verifies that all bounty awards are permitted by applicable laws, including (but not limited to) US trade sanctions and economic restrictions.\u003c/li\u003e\n\u003cli\u003eVerisign employees and their immediate family are not eligible to participate. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eVerisign Responsible Disclosure Policy\u003c/h2\u003e\n\n\u003cp\u003eVerisign expressly authorizes researching and reporting security issues in a manner that complies with the policies below, and, Verisign will not initiate a lawsuit against you or seek any law enforcement investigation against you in response to such authorized research and reports. We require that:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou make a good faith effort to avoid privacy violations and disruptions to others. You specifically should avoid unauthorized access to, or destruction of, data and interruption or degradation of our services.\u003c/li\u003e\n\u003cli\u003eYou do not exploit a security issue you discover for any reason. Impermissible exploitation includes, but is not limited to, actions intended to demonstrate the potential impact or risk of the vulnerability, such as attempts to compromise sensitive company data or probing for additional issues related to an eligible vulnerability in an in-scope target that exceeds any of the policies addressed here. \u003c/li\u003e\n\u003cli\u003eYou do not intentionally violate any applicable laws or regulations, including (but not limited to) laws and regulations prohibiting the unauthorized access to data.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are not authorized to access user data or company data, including (but not limited to) personally identifiable information or other data relating to an identified or identifiable natural person. If you inadvertently access personal or company data while investigating an issue, you are prohibited from saving, storing, transferring or otherwise further accessing any and all such data after discovery.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"a1c47aee-1ba6-450a-afbc-6ec94bbd508a","name":"In Scope Targets - Tier 1 Rewards","targets":[{"id":"730c20ee-5a7a-4b2d-9bbd-7a0c584c77d4","uri":null,"name":"epptool-ctld.verisign-grs.com (EPP service; DNS related)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8b972497-e434-45e2-b98d-67508afcfbbb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3b7b4aaf-a4fc-4547-9586-31b9fbf74611","uri":null,"name":"a.root-servers.net (DNS service; DNS related)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"84b60211-6be3-4f29-9b43-f44f98ba5455","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"32dc880c-2681-4799-96e9-6c3355999f09","uri":"","name":"j.root-servers.net (DNS service; DNS related)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ac4cab7b-5fc9-4fce-8675-5c9045c9dbad","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"6cafb941-08c3-42c5-bfe2-6fad5f8bdde4","uri":"","name":"*.gtld-servers.net (DNS service; DNS related)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c3fbc134-33be-40c6-9bd6-2f02f3740073","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"3cee8b56-b85d-432f-b8ce-fed5f34e11fe","p1MaxCents":1000000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":200000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eRewards Guidelines\u003c/h2\u003e\n\n\u003cp\u003eVerisign may consider a variety of factors when determining the bounty that a researcher should receive for reporting a vulnerability, consistent with the policies identified above. Generally, however, Verisign will follow separate payment scales for vulnerabilities identified with Verisign\u0026#39;s DNS and related infrastructure, on the one hand, and Verisign\u0026#39;s other in-scope targets, on the other hand. Rewards for qualifying bugs range from $100 to $10,000. The following table outlines the usual rewards chosen for the most common classes of bugs:\u003c/p\u003e\n\n\u003ctable\u003e\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eVulnerability\u003c/th\u003e\n\u003cth\u003eDNS and related infrastructure\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eRemote Code Execution\u003c/td\u003e\n\u003ctd\u003e$10,000\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eLogic flaw bugs leaking or bypassing significant security controls\u003c/td\u003e\n\u003ctd\u003e$5,000\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eSQL Injection\u003c/td\u003e\n\u003ctd\u003e$5,000\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eStored Cross Site Scripting\u003c/td\u003e\n\u003ctd\u003e$2,500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eReflected Cross Site Scripting\u003c/td\u003e\n\u003ctd\u003e$1,250\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e","rewardRangeData":{"1":{"min":5000,"max":10000},"2":{"min":2000,"max":5000},"3":{"min":500,"max":2000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"c089e1e3-49c3-479b-b383-57ec00374124","name":"In Scope Targets - Tier 2 Rewards","targets":[{"id":"02a9f7ce-7d32-40f2-8de0-1bcebbe8769c","uri":"https://www.verisign.com","name":"www.verisign.com (Website; non-DNS related)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7553e80a-82a7-494c-84de-834c44817467","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"02a9f7ce-7d32-40f2-8de0-1bcebbe8769c"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"02a9f7ce-7d32-40f2-8de0-1bcebbe8769c"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"02a9f7ce-7d32-40f2-8de0-1bcebbe8769c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"02a9f7ce-7d32-40f2-8de0-1bcebbe8769c"}],"recentChangeFlags":null},{"id":"3a70fde9-2908-4ca3-9a7a-3981f8e798bc","uri":"https://youcouldbe.com","name":"*.youcouldbe.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d08488d9-f735-46a0-8eaa-c226a92af03d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3a70fde9-2908-4ca3-9a7a-3981f8e798bc"}],"recentChangeFlags":null},{"id":"4d1dcc98-94ad-4801-a7ea-240bb3dd3402","uri":"https://blog.verisign.com","name":"blog.verisign.com (Website; non-DNS related)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6cf05b0c-f1e7-4743-933a-fc3af54b2a94","sortOrder":0},"sortOrder":0,"tags":[{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"4d1dcc98-94ad-4801-a7ea-240bb3dd3402"},{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"4d1dcc98-94ad-4801-a7ea-240bb3dd3402"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"4d1dcc98-94ad-4801-a7ea-240bb3dd3402"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4d1dcc98-94ad-4801-a7ea-240bb3dd3402"}],"recentChangeFlags":null},{"id":"3c1dcec6-f899-4472-931a-8b9b20305ca2","uri":"https://namestudioforsocial.com/","name":"*.namestudioforsocial.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e4fad514-385c-474d-b7c8-2893dcd66a55","sortOrder":0},"sortOrder":0,"tags":[{"id":"73ea470f-6fb9-4636-900b-259e5466f37e","name":"Apache httpd","targetId":"3c1dcec6-f899-4472-931a-8b9b20305ca2"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3c1dcec6-f899-4472-931a-8b9b20305ca2"}],"recentChangeFlags":null},{"id":"3914c669-e8cc-40a6-a8ec-3153a77f5632","uri":"https://namestudio.com","name":"*.namestudio.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a850a44a-b218-4393-90c2-2e7b6af7e8f1","sortOrder":0},"sortOrder":0,"tags":[{"id":"73ea470f-6fb9-4636-900b-259e5466f37e","name":"Apache httpd","targetId":"3914c669-e8cc-40a6-a8ec-3153a77f5632"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3914c669-e8cc-40a6-a8ec-3153a77f5632"}],"recentChangeFlags":null},{"id":"a49a0e2b-51ae-4397-bd39-9524176919e8","uri":"https://www.verisign.com","name":"*.verisign.com","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6cbfab65-46e2-48dd-a6ea-d315156f81ce","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a49a0e2b-51ae-4397-bd39-9524176919e8"}],"recentChangeFlags":null},{"id":"8b5b982b-f4e6-46eb-a5a9-0e9c686f2715","uri":"","name":"*.verisign-grs.com (DNS service; DNS related)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ccfabd2f-a6ef-4160-a936-2d24c7bf0ce5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"091cd874-cb65-4af9-bf44-a21b6a6c3005","p1MaxCents":500000,"p1MinCents":250000,"p2MaxCents":250000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eRewards Guidelines\u003c/h2\u003e\n\n\u003cp\u003eVerisign may consider a variety of factors when determining the bounty that a researcher should receive for reporting a vulnerability, consistent with the policies identified above. Generally, however, Verisign will follow separate payment scales for vulnerabilities identified with Verisign\u0026#39;s non DNS related infrastructure. Rewards for qualifying bugs range from $100 to $5000. The following table outlines the usual rewards chosen for the most common classes of bugs:\u003c/p\u003e\n\n\u003ctable\u003e\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eVulnerability\u003c/th\u003e\n\u003cth\u003eNon-DNS related infrastructure\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eRemote Code Execution\u003c/td\u003e\n\u003ctd\u003e$5,000\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eBypass Security Controls/Logic Flaw\u003c/td\u003e\n\u003ctd\u003e$2,500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eUnrestricted/Arbitrary file access\u003c/td\u003e\n\u003ctd\u003e$2,500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eStored Cross Site Scripting\u003c/td\u003e\n\u003ctd\u003e$1,500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eXSS  (Reflective vs Stored)\u003c/td\u003e\n\u003ctd\u003e$500 - $1,250\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e","rewardRangeData":{"1":{"min":2500,"max":5000},"2":{"min":1000,"max":2500},"3":{"min":500,"max":1000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"36bc7b3a-ba7a-4f94-b2f5-29d329a28a55","code":"verisign","state":"in_progress","endsAt":null,"bountyId":"ef086298-57d7-42e0-8912-37a711bb5da7","startsAt":"2018-07-19T17:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/6514/51ae/195faca4/82d1e10ae071fc4ea2d17dbf765baea7_250px-VRSNlogoAug2012.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":false,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-07-19T17:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/verisign","changelogs":"/engagements/verisign/changelog","submissions":null,"announcements":"/engagements/verisign/announcements","hallOfFame":"/engagements/verisign/hall_of_fames","crowdstream":"/engagements/verisign/crowdstream"},"announcementsCount":3,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/verisign/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=verisign\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/verisign/engagement_subscribers","engagementChangelogsUrl":"/engagements/verisign/changelog","publishedAt":"2026-05-27T13:33:00.969Z","engagementChangelogUrl":"/engagements/verisign/changelog/cab773d9-01e1-40cb-932b-7c5a4f2829fd","createUserFeedbacksUrl":"/engagements/verisign/feedbacks","engagementCrowdstreamUrl":"/engagements/verisign/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}