HomeinetMicrosoft Online Services Bug Bounty Program

Microsoft Online Services Bug Bounty Program

Microsoft today announced the Microsoft Online Services Bug Bounty Program , which offers security researchers rewards for reporting vulnerabilities in various online services provided by Microsoft . The company rewards the discovery and reporting of vulnerabilities with a minimum of $500, which increases depending on the impact of the vulnerability.

Microsoft Online Services Bug Bounty Program Microsoft Online Services Bug Bounty Program Microsoft Online Services Bug Bounty Program Microsoft Online Services Bug Bounty Program

The company says the vulnerabilities include:

Cross Site Scripting (XSS), Cross Site Request Forgery (CSRF), unauthorized cross-tenant data tampering or access (for multi-tenant services), insecure direct object references, injection flaws, authentication flaws, server-side code execution, privilege escalation and significant security misconfiguration.

The domains where the tests can be conducted are:

portal.office.com
* .outlook.com (Office 365 for business email service applications, excluding any consumer “outlook.com” services)
outlook.office365.com
login.microsoftonline.com
* .sharepoint.com
* .lync.com
* .officeapps.live.com
www.yammer.com
api.yammer.com
adminwebservice.microsoftonline.com
provisioningapi.microsoftonline.com
graph.windows.net

The company also provides a list of vulnerabilities that will not be patched:

  • Missing HTTP Security Headers (such as X-FRAME-OPTIONS) or cookie security flags (such as “httponly”).
  • Server-side information disclosure such as IPs, server names and most stack traces.
  • Bugs in the web application that only affect unsupported browsers and plugins.
  • Bugs used to enumerate or confirm the existence of users or tenants.
  • Bugs requiring unlikely user actions.
  • URL Redirects (unless combined with another flaw to produce a more severe vulnerability).
  • Vulnerabilities in platform technologies that are not unique to the online services in question (Apache or IIS vulnerabilities, for example).
  • "Cross Site Scripting" bugs in SharePoint that require "Designer" or higher privileges in the target's tenant.
  • Low impact CSRF bugs (such as logoff).
  • Denial of Service issues.
  • Cookie replay vulnerabilities.

You can report vulnerabilities in Microsoft to secure@microsoft.com.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS