At 8x8, we help companies get their employees, customers and applications talking to make people more connected and productive no matter where they are in the world. At 8x8 we value security and recognize the importance of ensuring the integrity and confidentiality of global communications. If you believe you've found a security issue in our product or service, we encourage you to notify us. This program serves as the default contact portal for issues not in-scope for our incentivized bounty programs.
8x8 will make a best effort to meet the following response targets for hackers participating in our program:
Time to first response (from report submit) - 2 business days
Time to triage (from report submit) - 2 business days
Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
Please do not discuss vulnerabilities (even resolved ones) outside of the program without express consent from 8x8.
Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.
Only interact with accounts you own or with explicit permission of the account holder. Please notify us immediately if you encounter exposure of information.
Follow HackerOne's disclosure guidelines.
While researching, we'd like to ask you to refrain from:
Any form of automation
Any activity that could lead to the disruption of our service (DoS)
Spamming
Social engineering (including phishing) of 8x8 staff or contractors
Any physical attempts against 8x8 property or data centers
Missing Security Headers (eg. HSTS, CSP, SPF, DMARC)
Missing Flags on Cookies
SSL issues (weak ciphers/key-size/BEAST/CRIME) -- Will consider expired certs on case-by-case basis
Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no security impact
Clickjacking
Rate Limiting (unless it constitutes a significant risk)
General low severity issues reported by automated scanners
Attacks requiring MITM or physical access to a user's device
Previously known vulnerable libraries without a working Proof of Concept
Comma Separated Values (CSV) injection without demonstrating a vulnerability
Rate limiting or brute-force issues on non-authentication endpoints
Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]
Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).
Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis.
Tab-nabbing
https://support.8x8.com/cloud-phone-service/voice/network-setup-voice/x-series-technical-requirements#IP_Ranges
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep 8x8 and our users safe!
Scope Type | Scope Name |
---|---|
android_application | org.vom8x8.sipua |
android_application | org.jitsi.meet |
application | Virtual Office Desktop |
ios_application | com.8x8.spot |
ios_application | com.atlassian.JitsiMeet.ios |
ios_application | com.8x8.meetings |
ios_application | com.yourcompany.Virtual-Office |
other | Intellectual Property on Public Domains |
web_application | *.dxi.eu |
web_application | sso.8x8.com |
web_application | *.contactnow.8x8.com |
web_application | accountmanager.8x8.com |
web_application | *.easycontactnow.com |
web_application | *.wavecell.com |
web_application | vcc-*.8x8.com |
web_application | *.ucverse.com |
web_application | *.jit.si |
web_application | *.jitsi.org |
web_application | *.packet8.net |
web_application | www.8x8.com |
web_application | *.8x8.com |
web_application | *.mycontactual.com |
web_application | *.sameroom.io |
web_application | get8x8.com |
web_application | support.8x8.com |
web_application | https://github.com/jitsi/ |
web_application | https://github.com/callstats-io/ |
web_application | *.callstats.io |
web_application | *.8x8e2e.com |
web_application | *.8x8pilot.com |
web_application | *.jitsi.net |
web_application | *.8x8.vc |
web_application | *.p8t.us |
web_application | *.8x8.id |
web_application | https://github.com/orgs/8x8/packages?repo_name=8x8_messaging_java_client |
web_application | *.8x8.uk |
web_application | *.8x8.co.uk |
web_application | *.fuze.com |
web_application | *.fuze.site |
web_application | *.thinkingphones.com |
web_application | *.thinkingphones.net |
web_application | *.adgjmp.net |
Scope Type | Scope Name |
---|---|
web_application | investors.8x8.com |
This program crawled on the 2020-01-09 is sorted as bounty.
FireBounty © 2015-2024