Beschreibung
Swiss Bankers is an internationally oriented financial-services provider. Our company is a leader in development, distribution and processing of prepaid credit cards and offers innovative solutions in cashless and secure payment transactions. With our mobile app, our customers are able to order, load and manage their credit cards. They’re also able to send and receive money globally within the MasterCard send network. The goal of this program is to find vulnerabilities in our system that leads to unauthorised account takeover, anomalies during the “add funds” process and irregular “send” transactions.
Regeln
Rules
Swiss Bankers operate various services (platforms, services). But only services from explicitly listed domains / URLs are in the scope of the Bug Bounty Program. All other domains or explicitly listed services are therefore not eligible for reward and do not fall under the Legal Safe Harbor Agreement.
By participating in this Bug Bounty Program, Friendly Hackers undertake to document information about any vulnerability found exclusively via the platform's designated reporting form and not in any other places. They also agree to keep the found vulnerability secret after reporting it on the platform. Finally, they undertake to upload to the platform any data from customers that they have obtained as part of a bug bounty program and to delete any local copies afterwards and not to distribute them further.
Hacking Methods
In participating in the program, ethical hackers agree not to use methods that would adversely affect the tested applications or their users. These include:
- Social engineering
- Spamming
- Phishing
- Denial-of-service attacks or other brute force attacks
- Physical attacks
In addition to the prohibited hacking methods listed above, Friendly Hackers are required to immediately discontinue vulnerability scanning if they determine that their conduct will result in a significant degradation (negative impact on regular users or on the operations team) of the Platform's or Service's operations.
Qualified vulnerabilities
Any design or implementation problem can be reported that is reproducible and affects security.
Typical examples:
- Cross Site Request Forgery (CSRF)
- Cross Site Scripting (XSS)
- Insecure Direct Object Reference
- Remote Code Execution (RCE) - Injection Flaws
- Information Leakage an Improper Error Handling
- Unauthorized access to properties or accounts
Other examples:
- Data/information leaks
- Possibility of data/information exfiltration
- Backdoors that can be actively exploited
- Potential for unauthorized system use
- Misconfigurations
Non-qualified vulnerabilities
The following vulnerabilities and forms of documentation are generally not wanted and will be rejected:
- Attacks that require physical access to a user's device or network
- Forms with missing CSRF tokens (unless the criticality exceeds CVSS level 5)
- Self-XSS
- The use of a library known to be vulnerable or publicly known to be broken (unless there is active evidence of exploitability)
- Reports from automated tools or scans without explanatory documentation
- Social engineering targeting individuals or entities of the organisation
- Denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks
- Bots, spam, bulk registration
- Submission of best practices that do not directly result in an exploitable vulnerability (e.g., certificate pinning, missing security headers)
- Use of vulnerable and "weak" cipher suites/ciphers
- Missing Rate limiting without further security impact
Scope
Not in scope: All (sub) domains and services that are not explicitly listed, are not in scope as e.g. www.swissbankers.ch (159.100.246.236, 159.100.248.24) extranet.swissbankers.ch events.swissbankers.ch
The identity verification (Intrum/IDNow) in the app is not in scope, however it’s allowed to follow this process to setup an account in the app.
In scope: The goal of this program is to find vulnerabilities in our system that leads to unauthorised account takeover, anomalies during the “add funds” process and irregular “send” transactions. It is also allowed to order physical cards. A limit of 6 cards per customer is configured. If this limit can be bypassed, please do not order more than 8-9 cards. See list of allowed URLs / targets. Please get in touch in advance if you think there should be another URL in scope to test the services.
- Main
*.swissbankers.ch (without www.) 193.134.38.32/27 194.209.51.176/29 195.65.247.128/28
- ch.swissbankers.mycard: Android App
Android app (customer portal) and all other called URLs in scope.
- swiss-bankers/id655514846: Apple app
Apple app (customer portal) and all other called URLs in scope.
- OpenTech Backend Services
OpenTech URLs and services needed for the Customer Portal and Mobile Apps:
- cf.openpay010.opentech.com/swissbankers
- openpay010.opentech.com/swissbankers
- www.securepayment-swissbankers.ch
- secure.swissbankers.ch
- auth.secure.swissbankers.ch
- storeidentifier.openpay.swissbankers.ch
- sbpsadminportal.opentech.com
- openpay011.opentech.com/swissbankers
- api010.opentech.com/PNMWS
- api012.opentech.com/PNMREST
- api012.opentech.com/PNMWSING/public/REST/ack
- acs.opentech.com/3ds/SBPS
- pubmauthapi.acs.opentech.com/3ds/console/SBPS
- api.acs.opentech.com/3ds/SBPS
- emv.acs.opentech.com/3ds/SBPS/areq
- api.emv.acs.opentech.com/3ds/SBPS
- openpay010.opentech.com/SBPSChallengeManager
- openpay010.opentech.com/SBPSAuthenticator
- Integration Hub
Rechtliches
The organisation gives their approval for Friendly Hackers to use hacking methods based on the specified bug bounty program. Due to this consent, the criminal liability criterion of unauthorized obtaining/unauthorized use and thus the criminal liability of the Friendly Hackers with regard to the criminal offenses in Art. 143 Swiss Criminal Code (Unauthorised obtaining of data) and Art. 143bis Swiss Criminal Code (Unauthorised access to a data processing system) does not apply.
Prämienstufen
Schweregrad | Prämie |
---|---|
Critical | CHF 3000-7500 |
High | CHF 1500-3000 |
Medium | CHF 200-1000 |
Low | CHF 50-200 |
Leaderboard
Rang | Benutzername | Punktzahl |
---|---|---|
1 | ndale | 92 |
2 | soman | 58 |
3 | hakupiku | 40 |
4 | irksomeorangutan | 37 |
5 | 3raasrk | 29 |
6 | User<29563897> | 1 |