52235 policies in database
Link to program      
2018-12-13
2020-01-15
Telefónica Germany logo
Thank
Gift
HOF
Reward

Telefónica Germany

If you find a vulnerability in one of our systems, we are happy to give you the opportunity to report this finding using our Responsible Disclosure Program.

For the time being disclosed vulnerabilities are not monetarily rewarded, however future changes to the award of findings are not excluded. Excluded from awards are legal representatives, current and former employees of Telefónica Germany GmbH & Co. OHG and its connected businesses and their employees. Minors may only participate with agreement of their legal representatives.

Our understanding of Responsible Disclosure

To responsibly disclose a detected vulnerability in one our systems:

  • Understand that all valid reports will be taken seriously by our teams; this in mind, do give us a reasonable period of time to evaluate the submission and respond accordingly.
  • While testing our systems you make every effort not to damage or restrict the availability of products, services or infrastructure.
  • You do not use a detected vulnerability to obtain more data than necessary for proving the vulnerability. Do not leverage any found vulnerability to obtain, spy, modify, delete or distribute any personal or sensitive data.
  • You agree to delete all personal and confidential information obtained during testing.
  • We will treat your submission confidentially and will not share your personal data with others unless required by law or judgement. It is possible to make your submission anonymously.
  • We will not legally pursue testing activity and submissions which respect the terms and scope set forth here.

Ratings:

For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.

Scope

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.

Learn more about Bugcrowd’s VRT.

In Scope

Scope Type Scope Name
android_application

Mein O2 Android Application

android_application

PartOS Android Application

android_application

O2 Business Android Application

ios_application

Mein O2 iOS Application

ios_application

PartOS iOS Application

ios_application

O2 Business iOS Application

web_application

*.telefonica.de

web_application

*.o2online.de

web_application

*.o2.de

web_application

*.o2business.de

web_application

*.o2service.de

web_application

*.o2spin.de

web_application

*.alditalk-kundenbetreuung.de

web_application

*.ayyildiz.de

web_application

*.base.de

web_application

*.blau.de

web_application

*.einfachprepaid.de

web_application

*.epos.vertriebspartner.de.o2.com

web_application

*.fonic.de

web_application

*.fonic-mobile.de

web_application

*.mediamarkt.o2service.de

web_application

*.mein.aetkasmart.de

web_application

*.mein.simfinity.de

web_application

*.nettokom.de

web_application

*.netzclub.net

web_application

*.norma-mobil.de

web_application

*.ortelmobile.de

web_application

*.saturn.o2service.de

web_application

*.sim-karte-aktivierung.blauworld.de

web_application

*.turkei-sim.de

web_application

https://vertriebspartner.de.o2.com/partos

web_application

*.whatsappsim.de

web_application

*.nova-mobil.de

Out of Scope

Scope Type Scope Name
web_application

https://www.alditalk.de

web_application

https://www.udldigital.de

web_application

https://www.wayra.co.uk

web_application

https://mobilfunk.tchibo.de

web_application

https://www.think-big.org

web_application

*.k-classic-mobil.de

web_application

*.pool.telefonica.de


The progam has been crawled by Firebounty on 2018-12-13 and updated on 2020-01-15, 389 reports have been received so far.

FireBounty © 2015-2024

Legal notices | Privacy policy