If you find a vulnerability in one of our systems, we are happy to give you the opportunity to report this finding using our Responsible Disclosure Program.
For the time being disclosed vulnerabilities are not monetarily rewarded, however future changes to the award of findings are not excluded. Excluded from awards are legal representatives, current and former employees of Telefónica Germany GmbH & Co. OHG and its connected businesses and their employees. Minors may only participate with agreement of their legal representatives.
To responsibly disclose a detected vulnerability in one our systems:
For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
Scope Type | Scope Name |
---|---|
android_application | Mein O2 Android Application |
android_application | PartOS Android Application |
android_application | O2 Business Android Application |
ios_application | Mein O2 iOS Application |
ios_application | PartOS iOS Application |
ios_application | O2 Business iOS Application |
web_application | *.telefonica.de |
web_application | *.o2online.de |
web_application | *.o2.de |
web_application | *.o2business.de |
web_application | *.o2service.de |
web_application | *.o2spin.de |
web_application | *.alditalk-kundenbetreuung.de |
web_application | *.ayyildiz.de |
web_application | *.base.de |
web_application | *.blau.de |
web_application | *.einfachprepaid.de |
web_application | *.epos.vertriebspartner.de.o2.com |
web_application | *.fonic.de |
web_application | *.fonic-mobile.de |
web_application | *.mediamarkt.o2service.de |
web_application | *.mein.aetkasmart.de |
web_application | *.mein.simfinity.de |
web_application | *.nettokom.de |
web_application | *.netzclub.net |
web_application | *.norma-mobil.de |
web_application | *.ortelmobile.de |
web_application | *.saturn.o2service.de |
web_application | *.sim-karte-aktivierung.blauworld.de |
web_application | *.turkei-sim.de |
web_application | https://vertriebspartner.de.o2.com/partos |
web_application | *.whatsappsim.de |
web_application | *.nova-mobil.de |
Scope Type | Scope Name |
---|---|
web_application | https://www.alditalk.de |
web_application | https://www.udldigital.de |
web_application | https://www.wayra.co.uk |
web_application | https://mobilfunk.tchibo.de |
web_application | https://www.think-big.org |
web_application | *.k-classic-mobil.de |
web_application | *.pool.telefonica.de |
The progam has been crawled by Firebounty on 2018-12-13 and updated on 2020-01-15, 389 reports have been received so far.
FireBounty © 2015-2024