17619 policies in database
Link to program      
2015-06-30
2019-11-02
Twilio logo
Thank
Gift
HOF
Reward

Reward

100 $ 

Twilio

Ensuring the security and integrity of the Twilio platform is critical to the service we provide to our customers. We are committed to providing a secure product and appreciate help from the community in responsibly identifying ways for us to improve Twilio. We will make an effort to respond as fast as possible.

If you would like to report abuse of SendGrid's service please see our spam/phish reporting page or email to abuse@sendgrid.com

Rules of Engagement

  • Bounties are awarded differently per product (see below for more details on payouts).
  • Network Level DDoS/DoS attacks are forbidden. Application volumetric DDoS/DoS attacks are forbidden, if you find a request that takes too long to answer report it, please do not try to DoS the service.
  • Interacting with real customers is forbidden.
  • To prevent being locked out please throttle automated testing
  • Please note, if you think you have found a problem but cannot prove it without accessing Twilio's Internal Systems, please submit your finding and we'll be happy to work with you for validation.
  • Please ensure that you use your @bugcrowdninja.com email address when creating accounts and testing
  • While creating any assets please use bugcrowd-<your email>-<random string>
  • Any POCs created as part of testing (such as npm packages) should follow the convention: twilio-bugcrowd-poc-<additional-string> and they should be deleted once the submission is triaged

For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.

Rewards:

Category Primary Secondary Other SendGrid Authy
P1 $2,500 - $8,000 $500 - $1,000 Kudos - $300 $2,000 - $4,000 $4,000 - $9,500
P2 $700 - $2,500 $200 - $500 Kudos - $200 $700 - $2000 $2,000 - $4,000
P3 $200 - $500 $100 - $200 Kudos - $150 $150 - $700 $750 - $1,500
P4 $100 - $150 Kudos -$100 Kudos - $100 $100 - $150 $250 - $500

Target Overview

Primary Targets

Secondary Targets

Other Targets

Any host/web property verified to be owned by Twilio (domains/IP space/etc.) but not listed in Primary or Secondary targets and not listed as Out of Scope.

Sendgrid Targets

https://sendgrid.com/
https://app.sendgrid.com/
https://signup.sendgrid.com/
https://api.sendgrid.com/
https://mc.sendgrid.com/
smtp.sendgrid.net

Authy Targets

NOTE: If a submission falls under Secondary, Other or Sendgrid targets, and has a significant impact, bounty may be increased at Twilio’s discretion.

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.

In Scope

Scope Type Scope Name
android_application

Authy Android App

api

api.twilio.com

api

Twilio APIs

api

api.sendgrid.com

api

Twilio Verify - https://verify.twilio.com

api

Twilio Authy API

api

Twilio Authy Dashboard API

ios_application

Authy iOS app

undefined

Twilio Wireless

undefined

Twilio Helper Libraries

undefined

Twilio SDKs

undefined

Twilio Console

undefined

Authy Desktop app

web_application

tsock.us1.twilio.com

web_application

.sip..twilio.com

web_application

Twilio WebRTC Client

web_application

Twilio CDNs (static*.twilio.com)

web_application

twilio.com/blog

web_application

https://build.twilio.com/s/

web_application

https://app.sendgrid.com/

web_application

https://signup.sendgrid.com/

web_application

https://mc.sendgrid.com/

web_application

smtp.sendgrid.net

web_application

https://sendgrid.com

web_application

Twilio Authy - https://api.authy.com

Out of Scope

Scope Type Scope Name
undefined

Ytica and its assets

undefined

TwimlBins

undefined

All Kurento domains

undefined

Third-party services used by SendGrid

web_application

store.twilio.com

web_application

Demo websites e.g. lab.authy.com

web_application

twiliotraining.com

web_application

www.twilio.com/labs

web_application

www.twilio.com/quest

web_application

surveys.twilio.com

web_application

support.sendgrid.com

web_application

status.sendgrid.com

web_application

support.twilio.com

web_application

s.signal.twilio.com

web_application

ahoy-eloqua.twilio.com

web_application

https://dashboard.authy.com


This program can reward you in USD, up to 9500 $.

FireBounty © 2015-2021

Legal notices