Bug Bounty Program Description 06-30-2024, 01:49 AM
#1
Bug Bounty Program Description
Primary Objective: Biometrics Security Evaluation and Data Protection
Our company is launching a bug bounty program with the specific goal of identifying and mitigating vulnerabilities in our biometric authentication system and data protection mechanisms. We seek security researchers to help ensure our system is robust and resistant to attacks.
Rewards
We offer monetary rewards for valid vulnerability reports. Rewards will vary based on the severity and impact of the vulnerabilities discovered.
Focus Areas
1. Biometric Authentication Bypass:
o Objective: Identify methods to bypass biometric authentication (fingerprint, facial recognition, etc.) without requiring the legitimate user's biometric data.
o Details: We are looking for techniques that allow access to accounts protected by biometrics without presenting the legitimate user's biometric data. This includes, but is not limited to, biometric data forgery, authentication system manipulation, and any form of bypass.
2. Database Exfiltration:
o Objective: Identify vulnerabilities that allow unauthorized access, extraction, or manipulation of data in our databases.
o Details: We are interested in techniques that enable an attacker to extract sensitive information stored in our databases. This may include SQL injection, privilege escalation, brute force attacks, etc.
Rules and Scope
• In-Scope Systems:
o Mobile applications: BBVA, Banco Azteca on iOS and Android
• Out-of-Scope Systems:
o Third-party infrastructure
o Internal services not accessible from the internet
• Report Requirements:
o Detailed description of the vulnerability
o Steps to reproduce the issue
o Potential impact
o Proof of concept (PoC)
• Conditions:
o Do not perform denial of service (DoS) attacks or any actions that could affect the availability of the service.
o Do not access, modify, or destroy data beyond what is necessary to demonstrate the vulnerability.
o Respect user privacy and do not misuse any information obtained.
How to Participate
To participate, To participate, please write to me. Researchers must follow the established rules and guidelines to be eligible for rewards.
Primary Objective: Biometrics Security Evaluation and Data Protection
Our company is launching a bug bounty program with the specific goal of identifying and mitigating vulnerabilities in our biometric authentication system and data protection mechanisms. We seek security researchers to help ensure our system is robust and resistant to attacks.
Rewards
We offer monetary rewards for valid vulnerability reports. Rewards will vary based on the severity and impact of the vulnerabilities discovered.
Focus Areas
1. Biometric Authentication Bypass:
o Objective: Identify methods to bypass biometric authentication (fingerprint, facial recognition, etc.) without requiring the legitimate user's biometric data.
o Details: We are looking for techniques that allow access to accounts protected by biometrics without presenting the legitimate user's biometric data. This includes, but is not limited to, biometric data forgery, authentication system manipulation, and any form of bypass.
2. Database Exfiltration:
o Objective: Identify vulnerabilities that allow unauthorized access, extraction, or manipulation of data in our databases.
o Details: We are interested in techniques that enable an attacker to extract sensitive information stored in our databases. This may include SQL injection, privilege escalation, brute force attacks, etc.
Rules and Scope
• In-Scope Systems:
o Mobile applications: BBVA, Banco Azteca on iOS and Android
• Out-of-Scope Systems:
o Third-party infrastructure
o Internal services not accessible from the internet
• Report Requirements:
o Detailed description of the vulnerability
o Steps to reproduce the issue
o Potential impact
o Proof of concept (PoC)
• Conditions:
o Do not perform denial of service (DoS) attacks or any actions that could affect the availability of the service.
o Do not access, modify, or destroy data beyond what is necessary to demonstrate the vulnerability.
o Respect user privacy and do not misuse any information obtained.
How to Participate
To participate, To participate, please write to me. Researchers must follow the established rules and guidelines to be eligible for rewards.
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)