Description

AS National Media & Tech (NMT) is a subsidiary of Axel Springer SE, a leading international media company. We develop and operate digital products for Germany’s top news brands, reaching over 50 million users each month. At Axel Springer, we stand for free journalism and unrestricted access to information, allowing people to make free decisions. To protect this, the security of our platforms and users is our top priority. Your contributions help us keep them safe.

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
50
150
300
1,250
2,500
Tier 1
€50 - €2,500
Tier 2
35
100
200
500
1,000
Tier 2
€35 - €1,000
Tier 3
15
50
75
250
500
Tier 3
€15 - €500
Rules of engagement
Not applicable
Not applicable
Not applicable
Not applicable

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Do not execute intrusive commands within production environments
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent also not POCs.

Validation times

We will always try to validate and accept your submissions as quickly as possible, for specific times you can check the average in the programme sidebar.

Assets

*.asadcdn.com

Tier 1
Wildcard
Tier 1
URL
Tier 1
URL
URL
URL

*.hey.bild.de

Tier 1
Wildcard
URL

*.auth.bild.de

Tier 1
Wildcard

*.sportbild.de

Tier 1
Wildcard

*.bild.tv

Tier 1
Wildcard

*.computerbild.de

Tier 1
Wildcard

18.184.198.198, 18.185.214.59, 18.194.109.179, 3.121.117.72, 3.121.138.10, 3.121.138.128, 3.121.138.134, 3.121.138.170, 3.121.138.33, 3.121.138.43, 3.124.248.208, 35.156.137.39

Tier 1
IP Range

dealer.prod.ps.axelspringer.de/purchases/*

Tier 1
Wildcard

*.germany.politico.eu

Tier 2
Wildcard

*.welt.de

Tier 2
Wildcard

*.bild.de

Tier 2
Wildcard

*.autobild.de

Tier 2
Wildcard

*.bz-berlin.de

Tier 2
Wildcard

*.spring-media.de

Tier 2
Wildcard

*.springtools.de

Tier 2
Wildcard
URL

*.as-nmt.de

Tier 2
Wildcard

*.ein-herz-fuer-kinder.de

Tier 3
Wildcard

*.fitbook.de

Tier 3
Wildcard

*.myhomebook.de

Tier 3
Wildcard

*.petbook-magazine.com/

Tier 3
Wildcard

*.petbook.de

Tier 3
Wildcard

*.stylebook.de

Tier 3
Wildcard

*.techbook.de

Tier 3
Wildcard

*.travelbook.de

Tier 3
Wildcard

*.wissen-sie-mehr.de

Tier 3
Wildcard

*.axelspringer.com

Out of scope
Wildcard
In scope

Our worst-case scenarios are:

  • Publishing fake news on our website.
  • Obtaining sensitive user data.
  • Command execution on production services.
Out of scope

General

  • If a reported vulnerability is already known to the company, it will be marked as duplicate.
  • Vulnerabilities without realistic exploit scenario(s) or realistic attack surface(s) are assigned a severity of "None".
  • Spam, social engineering and physical intrusion are not allowed under any circumstances.
  • Submissions based on software that no longer receives security updates will not be considered.
  • Attacks that require physical access to a victim's computer/device, man-in-the-middle or compromised user accounts are not permitted.
  • New vulnerabilities with severity of critical or exceptional are out of scope for the first 7 days.
  • New vulnerabilities with severity of high are out of scope for the first 14 days.
  • New vulnerabilities with severity of medium or lower are out of scope for the first 30 days.
  • Submissions without proof of concept will not be considered.
  • Multiple submissions based on the same piece of code, misconfiguration or dependency will be treated as a single submission. The deciding factor will be whether the problem can be fixed in one go.
  • We do not take responsibility for outgoing links.
  • All domains not listed as in scope above.
  • For the authenticated endpoint, we only accept cache poisoning submissions that are valid with changing authentication headers.
  • IDOR attacks for the Hey chat, which include a UUID, are out of scope and the risk is accepted. However, we would greatly appreciate submissions to enumerate or guess these UUIDs.

Application

  • Credential disclosure without proven business impact
  • Pre-Auth Account takeover/OAuth squatting
  • CORS misconfiguration on non-sensitive endpoints
  • Cross-site Request Forgery with no or low impact
  • Reverse tabnabbing
  • Clickjacking without proven impact/unrealistic user interaction
  • CSV Injection
  • Sessions not being invalidated (logout, enabling 2FA, etc.)
  • Tokens leaked to third parties
  • Anything related to email spoofing, SPF, DMARC or DKIM
  • Content injection without being able to modify the HTML
  • Username/email enumeration
  • Please only email bomb yourself
  • Homograph attacks
  • XMLRPC enabled
  • Not stripping metadata of files
Severity assessment

This program follows Intigriti's triage standards

FAQ

Do you have credentials to login into the applications?

No, we do not provide credentials for testing, but you are welcome to create your own account.

Can I give feedback to your program?

Yes certainly and we would appreciate use this feedback form for it.

Dos your program make use of retests?

Sometimes we will ask you to retest and offer up to a €50 bonus for doing so. If this offer is declined or expires and the submission is closed, we will not accept a submission with the same cause from the same researcher.

image.png
{180077} 3/6/2025, 1:57:46 PM
All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Overall stats
submissions received
1921
average payout
€223
accepted submissions
490
total payouts
N/A
Last 90 day response times
avg. time first response
< 5 days
avg. time to decide
< 2 weeks
avg. time to triage
< 6 days
Activity
10/25
logo
porygonez
created a submission
10/25
logo
thecave
created a submission
10/24
logo
porygonez
created a submission
10/24
Axel Springer SE
closed a submission
10/24
logo
behnam7491
created a submission
10/23
logo
k1nako
created a submission
10/23
logo
t0ann9uy3n
created a submission
10/22
logo
behnam7491
created a submission
10/22
logo
tganga306
created a submission
10/22
logo
mikey96
created a submission