DRACOON offers secure file sharing and collaboration services with two products, DRACOON Cloud and DRACOON Server. Both products support built-in end-to-end encryption and offer many features tailored for large organizations, such as a complex roles and permissions system, SSO integration, auditing and reporting features.
With this bug bounty program, we want to reinforce our commitment to security and reward security researchers for helping us protect our customers' data.
DRACOON wants to increase the security of its products by inviting security researchers to analyze the implementation of security measures in its product and to identify existing vulnerabilities. In order to achieve this goal together, it is important to us that the following rules are adhered to.
We are happy to thank everyone who submits valid reports to improve the security of our cloud service, however only those that meet the following eligibility requirements may receive a monetary reward:
Core - This service is the heart of the backend. It is responsible for file upload, download, sharing, user and role management.
OAuth - Responsible for user authentication. Implements OAuth2.
S3 Storage - Storage location of binary data. Accessible via internet and heavy use of pre-signed S3 URLs to allow direct transfer between client app and storage.
Media - Responsible for image downscaling (e.g. for thumbnails).
Reporting - Responsible for generating various reports triggered by the user (e.g. reports on user activity). Creates PDF and CSV files.
WebDAV - Proxy service that allows to connect to DRACOON via WebDAV protocol.
Branding - Allows customers to customize appearance. Manages customer branding configurations (e.g. logo, email signatures).
Signing - Acts as a proxy to our signing partner FP-Sign. Responsible for sending signing requests and storing signed documents in DRACOON.
Web App - The main web application to access DRACOON via a browser. This is the only full-feature client.
Desktop Apps - Sync client for Windows and Mac. Mounts DRACOON as a virtual disk on the end user’s device.
Mobile Apps - Native apps for Android and iOS, that provide a subset of the features.
MS Teams App - App for MS Teams.
Outlook Add-In - Add-In for MS Outlook. Allows to convert attachments to share links.
Swagger UI - Swagger UI is an interactive API documentation. Most services provide a public Swagger UI client. See useful links section.
Area | Scope Type | Scope URL | DRACOON Cloud | DRACOON Server |
---|---|---|---|---|
Backend | Core Service | /api | yes | yes |
Backend | OAuth Service | /oauth | yes | yes |
Backend | S3 Storage | https://0-2744452194.s3.nbg01.de.dracoon.io | yes | no |
Backend | Media Service | /mediaserver | yes | no |
Backend | Reporting Service | /reporting[/api] | yes | no |
Backend | WebDAV Proxy | /webdav | yes | yes |
Frontend | Web App | / | yes | yes |
Scope Type | Scope Name |
---|---|
api | https://bounty-cloud.dracoon.app/api |
api | https://bounty-cloud.dracoon.app/reporting/api |
api | https://bounty-server.dracoon.app/api |
api | https://bounty-server.dracoon.app/reporting/api |
web_application | https://bounty-cloud.dracoon.app/oauth |
web_application | https://0-2744452194.s3.nbg01.de.dracoon.io |
web_application | https://bounty-cloud.dracoon.app/mediaserver |
web_application | https://bounty-cloud.dracoon.app/webdav |
web_application | https://bounty-cloud.dracoon.app/ |
web_application | https://bounty-server.dracoon.app/oauth |
web_application | https://bounty-server.dracoon.app/webdav |
web_application | https://bounty-server.dracoon.app/ |
Scope Type | Scope Name |
---|---|
undefined | Any other host, tenant or service than the ones explicitly stated. |
undefined | *.dracoon.app (with the exceptions of bounty-cloud.dracoon.app and bounty-server.dracoon.app) |
undefined | *.dracoon.io (with the exception of https://0-2744452194.s3.nbg01.de.dracoon.io) |
web_application | www.dracoon.com |
web_application | *.dracoon.com |
web_application | *.dracoon.net |
web_application | *.dracoon.team |
web_application | *.fp-sign.com |
web_application | *.usersnap.com |
web_application | *.gdata.com |
web_application | *.retarus.com |
Firebounty have crawled on 2024-07-01 the program DRACOON – Bug Bounty Program on the platform Yeswehack.
FireBounty © 2015-2025