- gitlab.isc.orgother- lists.isc.orgother- Any asset that is not explicitly…cluded in our program's scopeother— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for BIND 9 Bug Bounty Program.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
first indexed
28d ago · 1 in-scope assets
// only one snapshot on record — changes appear from the next ingest onward
{
"id": "bind-bug-bounty-program",
"name": "BIND 9 Bug Bounty Program",
"public": true,
"managed": null,
"targets": {
"in_scope": [
{
"type": "open-source",
"target": "https://gitlab.isc.org/isc-projects/bind9"
}
],
"out_of_scope": [
{
"type": "other",
"target": "- gitlab.isc.org"
},
{
"type": "other",
"target": "- lists.isc.org"
},
{
"type": "other",
"target": "- Any asset that is not explicitly included in our program's scope"
},
{
"type": "other",
"target": "- Any third parties' or community assets (e.g. packages or versions not created and published by ISC)"
},
{
"type": "other",
"target": "- Any deprecated versions and versions other than the current stable/official version"
},
{
"type": "other",
"target": "- Any local implementation of the project/implementation belonging to third parties"
},
{
"type": "other",
"target": "- Vulnerabilities in the DNS protocol that are not specific to the BIND 9 implementation (while we are interested in these, they are out of scope of this Bug Bounty program)"
},
{
"type": "other",
"target": "- Any vulnerability that requires admin or admin-like access (see above for more details) — this includes access to files on disk, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk, and authenticated access to change the zone file contents (zone transfers, DNS update)"
}
]
},
"disabled": false,
"max_bounty": 10000,
"min_bounty": 100
}- Any third parties' or community …created and published by ISC)other- Any deprecated versions and vers…rrent stable/official versionother- Any local implementation of the …on belonging to third partiesother- Vulnerabilities in the DNS proto…e of this Bug Bounty program)other- Any vulnerability that requires … (zone transfers, DNS update)other