Caffeine is a social broadcasting platform for gaming, entertainment, and the creative arts. Our goal with this bug bounty program is give researchers a responsible way to disclose vulnerabilities, allow us to build a more secure service for all our users, and reward you for your hard work.
For this program, we are inviting researchers to test our websites, mobile apps, API services, auxiliary services and our Windows 10 broadcasting software.
Eligibility to participate in the program is contingent on your ability abide by the following - inability to do so will result in disqualification from rewards and/or removal from the program.
Do Not Create more than 5 test accounts
Do not attempt any tests on a broadcaster's live broadcast other than your own (www.caffeine.tv/yourusername)
Scanning is allowed, but keep in mind this is running on AWS who do actively block some scans.
Caffeine.tv runs automated scans from Acunetix, Zap, Nessus, et al., against the in-scope targets – so using these tools is likely of minimal utility to researchers. As such, please avoid using them unless for targeted, specific testing, and then only at less than six requests per second / less than 50 automated requests on a single endpoint.
Caffeine uses an OAuth 2.0 style authentication system with a Request Token and an Access Token. Currently, Access Tokens expire after 15 minutes.
Submissions related to the access token not immediately expiring will be considered ineligible for reward (such as changing of password or logout).
If a researcher is able to demonstrate that the access token is valid for more than 15 minutes, that is likely to be viewed as a priority.
Refresh Tokens will expire immediately upon changing password.
This program adheres to the Bugcrowd Vulnerability Rating Taxonomy for the prioritization/rating of findings.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | Caffeine Android Application |
api | https://api.caffeine.tv/ |
api | https://payments.caffeine.tv |
api | https://realtime.caffeine.tv/ |
api | https://images.caffeine.tv/ |
ios_application | Caffeine iOS Application |
web_application | https://www.caffeine.tv/ |
web_application | https://preview.caffeine.tv/ |
web_application | https://static.caffeine.tv/ |
web_application | https://build.caffeine.tv/ |
web_application | caffeine.exe |
web_application | caffeine-helper.x86.exe |
web_application | caffeine-helper.x64.exe |
web_application | *.rtcdn.caffeine.tv |
Scope Type | Scope Name |
---|---|
api | https://events.caffeine.tv/ |
undefined | Any Third Party Software Applications (Zendesk, etc) |
web_application | Caffeine.custhelp.com |
This program crawled on the 2018-03-22 is sorted as bounty.
FireBounty © 2015-2024