52235 policies in database
Link to program      
2020-01-09
2020-01-14
8x8 logo
Thank
Gift
HOF
Reward

8x8

At 8x8, we help companies get their employees, customers and applications talking to make people more connected and productive no matter where they are in the world. At 8x8 we value security and recognize the importance of ensuring the integrity and confidentiality of global communications. If you believe you've found a security issue in our product or service, we encourage you to notify us. This program serves as the default contact portal for issues not in-scope for our incentivized bounty programs.

Response Targets

8x8 will make a best effort to meet the following response targets for hackers participating in our program:

  • Time to first response (from report submit) - 2 business days

  • Time to triage (from report submit) - 2 business days

Disclosure Policy

  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.

  • Please do not discuss vulnerabilities (even resolved ones) outside of the program without express consent from 8x8.

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.

  • Only interact with accounts you own or with explicit permission of the account holder. Please notify us immediately if you encounter exposure of information.

  • Follow HackerOne's disclosure guidelines.

Exclusions

While researching, we'd like to ask you to refrain from:

  • Any form of automation

  • Any activity that could lead to the disruption of our service (DoS)

  • Spamming

  • Social engineering (including phishing) of 8x8 staff or contractors

  • Any physical attempts against 8x8 property or data centers

  • Missing Security Headers (eg. HSTS, CSP, SPF, DMARC)

  • Missing Flags on Cookies

  • SSL issues (weak ciphers/key-size/BEAST/CRIME) -- Will consider expired certs on case-by-case basis

  • Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no security impact

  • Clickjacking

  • Rate Limiting (unless it constitutes a significant risk)

  • General low severity issues reported by automated scanners

  • Attacks requiring MITM or physical access to a user's device

  • Previously known vulnerable libraries without a working Proof of Concept

  • Comma Separated Values (CSV) injection without demonstrating a vulnerability

  • Rate limiting or brute-force issues on non-authentication endpoints

  • Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]

  • Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).

  • Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis.

  • Tab-nabbing

8x8 IP Ranges & Domains

https://support.8x8.com/cloud-phone-service/voice/network-setup-voice/x-series-technical-requirements#IP_Ranges

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Thank you for helping keep 8x8 and our users safe!

In Scope

Scope Type Scope Name
android_application

org.vom8x8.sipua

android_application

org.jitsi.meet

application

Virtual Office Desktop

ios_application

com.8x8.spot

ios_application

com.atlassian.JitsiMeet.ios

ios_application

com.8x8.meetings

ios_application

com.yourcompany.Virtual-Office

other

Intellectual Property on Public Domains

web_application

*.dxi.eu

web_application

sso.8x8.com

web_application

*.contactnow.8x8.com

web_application

accountmanager.8x8.com

web_application

*.easycontactnow.com

web_application

*.wavecell.com

web_application

vcc-*.8x8.com

web_application

*.ucverse.com

web_application

*.jit.si

web_application

*.jitsi.org

web_application

*.packet8.net

web_application

www.8x8.com

web_application

*.8x8.com

web_application

*.mycontactual.com

web_application

*.sameroom.io

web_application

get8x8.com

web_application

support.8x8.com

web_application

https://github.com/jitsi/

web_application

https://github.com/callstats-io/

web_application

*.callstats.io

web_application

*.8x8e2e.com

web_application

*.8x8pilot.com

web_application

*.jitsi.net

web_application

*.8x8.vc

web_application

*.p8t.us

web_application

*.8x8.id

web_application

https://github.com/orgs/8x8/packages?repo_name=8x8_messaging_java_client

web_application

*.8x8.uk

web_application

*.8x8.co.uk

web_application

*.fuze.com

web_application

*.fuze.site

web_application

*.thinkingphones.com

web_application

*.thinkingphones.net

web_application

*.adgjmp.net

Out of Scope

Scope Type Scope Name
web_application

investors.8x8.com


This program crawled on the 2020-01-09 is sorted as bounty.

FireBounty © 2015-2024

Legal notices | Privacy policy