Banner object (1)

Hack and Take the Cash !

844 bounties in database
  Back Link to program      
26/11/2019
Genasys Technologies logo
Thanks
Gift
Hall of Fame
Reward

Genasys Technologies

Genasys Technologies provides insurance software solutions for various types of companies in the insurance space. All our software is developed in-house. Our strategy is exposing our back-end system through a growing set of API endpoints. Moving from private networks to public internet introduces new risks. If you believe you've found a security issue in our products, we encourage you to notify us.

Disclosure Policy

  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
  • Provide us a reasonable amount of time to resolve the issue before any disclosure to the public or a third-party.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.

Exclusions

While researching, we'd like to ask you to refrain from:

  • Denial of service
  • Spamming
  • Sending email to any email addresses you do not own
  • Social engineering (including phishing) of Genasys Technologies staff or contractors
  • Any physical attempts against Genasys Technologies property or data centers
  • Submitting unvalidated reports from automated tools

Out-of-scope

The following items are considered out-of-scope:

  • Any other asset or domain not explicitly listed as in-scope. Note that https:// genasystech.co.uk / is out of scope - it is hosted by an external marketing company. Only target assets at https:// staging.genasystech.co.uk/
  • Automated scanning against any contact/submission form will not be tolerated
  • Clickjacking on pages with no sensitive actions
  • Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
  • Attacks requiring MITM or physical access to a user's device.
  • Previously known vulnerable libraries without a working Proof of Concept.
  • Comma Separated Values (CSV) injection without demonstrating a vulnerability.
  • Missing best practices in SSL/TLS configuration.
  • Any activity that could lead to the disruption of our service (DoS).
  • Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
  • Rate limiting or bruteforce issues on non-authentication endpoints
  • Missing best practices in Content Security Policy.
  • Missing HttpOnly or Secure flags on cookies
  • Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)
  • Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]
  • Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).
  • Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis.
  • Tabnabbing
  • Open redirect - unless an additional security impact can be demonstrated
  • Issues that require unlikely user interaction
  • Self-XSS

Guidance

We are most interested in security faults within our custom applications and web services. For this reason, there is no WAF or rate limiting and our API documentation is published.

Direct-to-Consumer (D2C)

General public users have access to D2C API as well as a white-labeled JavaScript application. This is used for purchasing insurance. Use SagePay test card numbers to finalize payment on the staging environment (https://www.sagepay.co.uk/support/12/36/test-card-details-for-your-test- transactions __).

System Users

System users have access to SKi API and 4Web, a web application for insurers, brokers and agents to process policy sales and claims. Different users have different privileges based on a RBAC security model.

In order to access these applications, you can create your own system user at https://staging.genasystech.co.uk/CreateBrokerAccount/ __. Note that this utility itself is not in scope for testing, but we would be interested if injected values cause issues in any in-scope applications.

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

We appreciate your efforts in helping us protect our clients' data.

In Scope

Scope Type Scope Name
web_application

staging.genasystech.co.uk/d2c

web_application

staging.genasystech.co.uk/4web

web_application

staging.genasystech.co.uk/d2c-api

web_application

staging.genasystech.co.uk/skiapi

web_application

https://staging.genasystech.co.uk/d2c-api/swagger/index.html __

web_application

https://staging.genasystech.co.uk/skiapi/swagger/ui/index.html __


This program crawled on the 2019-11-26 is sorted as bounty.

FireBounty © 2015-2019

Legal notices