Banner object (1)

5307 policies in database
  Back Link to program      
09/01/2020
8x8 logo
Thanks
Gift
Hall of Fame
Reward

8x8

At 8x8, we help companies get their employees, customers and applications talking to make people more connected and productive no matter where they are in the world. At 8x8 we value security and recognize the importance of ensuring the integrity and confidentially of global communications. If you believe you've found a security issue in our product or service, we encourage you to notify us. This program serves as the default contact portal for issues not covered by an incentivized program.

Response Targets

8x8 will make a best effort to meet the following response targets for hackers participating in our program:

  • Time to first response (from report submit) - 2 business days
  • Time to triage (from report submit) - 2 business days

Disclosure Policy

  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
  • Please do not discuss vulnerabilities (even resolved ones) outside of the program without express consent from 8x8.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.
  • Only interact with accounts you own or with explicit permission of the account holder. Please notify us immediately if you encounter exposure of information.

Exclusions

While researching, we'd like to ask you to refrain from:

  • Any form of automation
  • Denial of service
  • Spamming
  • Social engineering (including phishing) of 8x8 staff or contractors
  • Any physical attempts against 8x8 property or data centers
  • Missing Security Headers (eg. HSTS, CSP, SPF)
  • Missing Flags on Cookies
  • SSL issues (weak ciphers/key-size/BEAST/CRIME)
  • CSRF without any security impact
  • Clickjacking
  • Rate Limiting (unless it constitutes a significant risk)
  • General low severity issues reported by automated scanners

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Thank you for helping keep 8x8 and our users safe!

In Scope

Scope Type Scope Name
android_application

org.vom8x8.sipua

android_application

https://play.google.com/store/apps/details?id=org.vom8x8.sipua&hl=None

application

https://support.8x8.com/us/Cloud_Phone_Service/Voice/Virtual_Office_Desktop/Download_Virtual_Office_Desktop

ios_application

https://apps.apple.com/app/id348177448

ios_application

com.8x8.spot

ios_application

https://apps.apple.com/us/app/8x8-meeting-rooms/id1468264023

ios_application

com.atlassian.JitsiMeet.ios

ios_application

https://apps.apple.com/us/app/jitsi-meet/id1165103905

ios_application

com.8x8.meetings

ios_application

https://apps.apple.com/us/app/8x8-video-meetings/id1473422060

web_application

*.dxi.eu

web_application

sso.8x8.com

web_application

*.contactnow.8x8.com

web_application

accountmanager.8x8.com

web_application

*.easycontactnow.com

web_application

*.wavecell.com

web_application

vcc-*.8x8.com

web_application

*.ucverse.com

web_application

8x8.vc

web_application

*.jit.si

web_application

*.jitsi.org

web_application

*.packet8.net

web_application

www.8x8.com

web_application

*.8x8.com

web_application

*.mycontactual.com

web_application

*.sameroom.io

web_application

get8x8.com

web_application

support.8x8.com

web_application

callstats.io

web_application

https://github.com/jitsi/

web_application

https://github.com/callstats-io/


This program crawled on the 2020-01-09 is sorted as bounty.

FireBounty © 2015-2020

Legal notices