Thüringer Aufbaubank Bug Bounty Program
Bounty Range
$50 - $7,000
external program
Bounty Range
$50 - $7,000
external program
The Thüringer Aufbaubank (TAB) is the central development institute of the German Free State of Thuringia. It was founded in 1992 as an institution under public law. The tasks of the bank include, in addition to economic development, the promotion of housing and urban development, the promotion of technology, the financing of public customers, agriculture, environmental protection and infrastructure.
We believe that no technology is perfect and that working with skilled security researchers is crucial in identifying weaknesses in our technology.
If you believe you've found a security bug in our service, we are happy to work with you to resolve the issue promptly and ensure you are fairly rewarded for your discovery.
Our targets in scope are the web applications listed below. With our web applications, you can submit and manage funding applications to the Thüringer Aufbaubank directly on the Internet. Here you also have the possibility to get detailed information about the processing status of your applications at any time, even if they have not been submitted via the portal.
We are happy to thank everyone who submits valid reports which help us improve the security of Thüringer Aufbaubank however, only those that meet the following eligibility requirements may receive a monetary reward:
You must be the first reporter of a vulnerability.
The vulnerability must be a qualifying vulnerability (see below)
Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through yeswehack.com
You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary.
You must avoid tests that could cause degradation or interruption of our service (refrain from using automated tools, and limit yourself about requests per second).
You must not leak, manipulate, or destroy any sensitive data (personally identifiable information). If access to sensitive data is necessary it must be limited exclusively to the data necessary to prove the security issue.
You must not be a former or current employee of Thüringer Aufbaubank or one of its contractor.
Reports about vulnerabilities are examined by our security analysts.
Our analysis is always based on worst case exploitation of the vulnerability, as is the reward we pay.
No vulnerability disclosure, including partial is allowed for the moment.
You must use a yesWeHack email address if you register an account on one of our web applications to hunt for bugs. You will find your alias in https://yeswehack.com/user/tools/email-alias
| Asset value | CVSS Low | CVSS Medium | CVSS High | CVSS Critical |
|---|---|---|---|---|
| Critical | €50 | €200 | €2,000 | €7,000 |
| Scope | Type | Asset value |
|---|---|---|
| https://thueringer-foerderportal.eu | Web application | Critical |
| https://ecohesion.aufbaubank.de | Web application | Critical |
| https://login.aufbaubank.de | Web application | Critical |
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program's scope and policy.
| Type of leak | Source of leak is in-scope | Source of leak belongs to the Organization and is out-of-scope | Source of leak does not belong to the Organization and is out-of-scope |
|---|---|---|---|
| Impact is in-scope (e.g. valid credentials on an in-scope asset) | Eligible | Eligible | Not eligible |
| Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) | Eligible | Not eligible | Not eligible |
To test our scopes, please register as a new user in the respective web applications. Please only use a yesWeHack email address for this.
Please use the User-Agent -BugBounty-TA-31337 during your testings. For that, you may for instance use the following extension to easily configure your BurpSuite: https://github.com/yeswehack/YesWeBurp
Please append to your user-agent header the following value: ' -BugBounty-TA-31337 '.
When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.
For more information, see https://helpcenter.yeswehack.io/hunter/hunter-collaboration