OneWeb looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe.
OneWeb is the world’s second biggest satellite operator. As a global communications company powered from Low Earth Orbit (LEO), OneWeb is building an advanced satellite constellation to connect businesses, telecom, and governments with high speed, low-latency, internet connectivity. OneWeb brings secure, resilient connectivity, through a network of distribution partners, from pole to pole, across oceans and continents.
OneWeb will make a best effort to meet the following SLAs for hackers participating in our program:
| Type of Response | SLA in business days |
| ------------- | ------------- |
| First Response | 1 day |
| Time to Triage | 1 day |
| Time to Resolution | depends on severity and complexity |
We’ll try to keep you informed about our progress throughout the process.
Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.
Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced).
Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
Social engineering (e.g. phishing, vishing, smishing) is prohibited.
Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of any OneWeb service. Only interact with accounts you own or with explicit permission of the account holder.
We have listed the assets in scope for this program, however, if you have found a potential vulnerability (excluding the out of scope vulnerabilities listed below) on any product, system or asset you believe belongs to OneWeb, please submit it through this program as we would like to hear about it.
Causing, or attempting to cause, a Denial of Service (DoS) condition
Accessing, or attempting to access, data or information that does not belong to you
Destroying or corrupting, or attempting to destroy or corrupt, data or information that does not belong to you
Physical or social engineering attacks (Including Phishing/Smishing etc.)
Attacks against Microsoft infrastructure
Attacks against AWS infrastructure
Security vulnerabilities in third-party products (SaaS) or websites that are not under OneWeb direct control
remotehelp.oneweb.net is out of scope - this is operated by a third party and cannot currently be included
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep OneWeb and our users safe!
Scope Type | Scope Name |
---|---|
other | E-mail Configuration (SPF, DKIM, DMARC) |
web_application | *.oneweb.net |
web_application | *.oneweb.world |
web_application | *.oneweb.systems |
web_application | *.oneweb.build |
web_application | *.oneweb.qa |
web_application | *.oneweb.training |
web_application | *.owscc.net |
web_application | *.world-vu.net |
web_application | 23.160.32.0/24 |
web_application | 103.147.48.0/23 |
web_application | 207.32.208.0/22 |
web_application | 2604:fdc0::/32 |
web_application | 45.147.188.0/22 |
web_application | 102.222.138.0/23 |
web_application | www.oneweb.net |
web_application | ephemeris.oneweb.net |
Scope Type | Scope Name |
---|---|
web_application | remotehelp.oneweb.net |
web_application | autodiscover.oneweb.net |
web_application | autodiscover.world-vu.net |
web_application | *.staging.oneweb.build |
This policy crawled by Onyphe on the 2021-09-27 is sorted as bounty.
FireBounty © 2015-2024