79207 policies in database
Link to program      
2024-07-01
2025-03-11
DRACOON – Bug Bounty Program logo
Thank
Gift
HOF
Reward

Reward

DRACOON – Bug Bounty Program

DRACOON

DRACOON offers secure file sharing and collaboration services with two products, DRACOON Cloud and DRACOON Server. Both products support built-in end-to-end encryption and offer many features tailored for large organizations, such as a complex roles and permissions system, SSO integration, auditing and reporting features.

With this bug bounty program, we want to reinforce our commitment to security and reward security researchers for helping us protect our customers' data.

Program Rules

DRACOON wants to increase the security of its products by inviting security researchers to analyze the implementation of security measures in its product and to identify existing vulnerabilities. In order to achieve this goal together, it is important to us that the following rules are adhered to.

  • (D)DoS attacks on our infrastructure are strictly prohibited. This includes (but is not limited to) all applications, services, servers and network infrastructure.
  • Do not carry out load-based attacks (e.g. automated scanners that create a large number of requests).
  • Do not interfere with any box that is not listed within the program scope.
  • Do not decommission any boxes.
  • Do not change network configuration.
  • Do not change passwords of accounts (unless it’s your own) or delete other accounts.
  • Do not extract information and disclose it if you should gain access to it irregularly.
  • Do not alter, modify or delete any information stored in our cloud if you should gain access to it irregularly.
  • Do not publish (even partially) any vulnerabilities that are found.

Reward Eligibility

We are happy to thank everyone who submits valid reports to improve the security of our cloud service, however only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability (see below).
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through http://yeswehack.com.
  • The vulnerability report must contain the following elements:
    1. A clear textual description of the vulnerability, how it can be exploited, its security impact and remediation advice.
    2. A proof of the exploitation of the vulnerability (e.g. screenshots, proof of concept code).
    3. The preconditions and steps required to reproduce the issue including code snippets, commands, request information, payloads, etc.
  • You must not be a former or current employee of our company or one of its contractors.
  • As DRACOON Cloud and DRACOON Server share the majority of the source code, we consider the same attack on both systems in scope as duplicate.

DRACOON Infrastructure Overview

Description of services

Services in scope

Core - This service is the heart of the backend. It is responsible for file upload, download, sharing, user and role management.
OAuth - Responsible for user authentication. Implements OAuth2.
S3 Storage - Storage location of binary data. Accessible via internet and heavy use of pre-signed S3 URLs to allow direct transfer between client app and storage.
Media - Responsible for image downscaling (e.g. for thumbnails).
Reporting - Responsible for generating various reports triggered by the user (e.g. reports on user activity). Creates PDF and CSV files.
WebDAV - Proxy service that allows to connect to DRACOON via WebDAV protocol.

Services out of scope

Branding - Allows customers to customize appearance. Manages customer branding configurations (e.g. logo, email signatures).
Signing - Acts as a proxy to our signing partner FP-Sign. Responsible for sending signing requests and storing signed documents in DRACOON.

Description of clients

Clients in scope

Web App - The main web application to access DRACOON via a browser. This is the only full-feature client.

Clients out of scope

Desktop Apps - Sync client for Windows and Mac. Mounts DRACOON as a virtual disk on the end user’s device.
Mobile Apps - Native apps for Android and iOS, that provide a subset of the features.
MS Teams App - App for MS Teams.
Outlook Add-In - Add-In for MS Outlook. Allows to convert attachments to share links.
Swagger UI - Swagger UI is an interactive API documentation. Most services provide a public Swagger UI client. See useful links section.

Area Scope Type Scope URL DRACOON Cloud DRACOON Server
Backend Core Service /api yes yes
Backend  OAuth Service /oauth yes yes
Backend S3 Storage https://0-2744452194.s3.nbg01.de.dracoon.io yes no
Backend Media Service /mediaserver yes no
Backend Reporting Service /reporting[/api] yes no
Backend WebDAV Proxy /webdav yes yes
Frontend Web App / yes yes

Useful links

In Scope

Scope Type Scope Name
api

https://bounty-cloud.dracoon.app/api

api

https://bounty-cloud.dracoon.app/reporting/api

api

https://bounty-server.dracoon.app/api

api

https://bounty-server.dracoon.app/reporting/api

web_application

https://bounty-cloud.dracoon.app/oauth

web_application

https://0-2744452194.s3.nbg01.de.dracoon.io

web_application

https://bounty-cloud.dracoon.app/mediaserver

web_application

https://bounty-cloud.dracoon.app/webdav

web_application

https://bounty-cloud.dracoon.app/

web_application

https://bounty-server.dracoon.app/oauth

web_application

https://bounty-server.dracoon.app/webdav

web_application

https://bounty-server.dracoon.app/

Out of Scope

Scope Type Scope Name
undefined

Any other host, tenant or service than the ones explicitly stated.

undefined

*.dracoon.app (with the exceptions of bounty-cloud.dracoon.app and bounty-server.dracoon.app)

undefined

*.dracoon.io (with the exception of https://0-2744452194.s3.nbg01.de.dracoon.io)

web_application

www.dracoon.com

web_application

*.dracoon.com

web_application

*.dracoon.net

web_application

*.dracoon.team

web_application

*.fp-sign.com

web_application

*.usersnap.com

web_application

*.gdata.com

web_application

*.retarus.com


Firebounty have crawled on 2024-07-01 the program DRACOON – Bug Bounty Program on the platform Yeswehack.

FireBounty © 2015-2025

Legal notices | Privacy policy