Description

AS National Media & Tech (NMT) is a subsidiary of Axel Springer SE, a leading international media company. We develop and operate digital products for Germany’s top news brands, reaching over 50 million users each month. At Axel Springer, we stand for free journalism and unrestricted access to information, allowing people to make free decisions. To protect this, the security of our platforms and users is our top priority. Your contributions help us keep them safe.

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
50
150
300
1,250
2,500
Tier 1
€50 - €2,500
Tier 2
35
100
200
500
1,000
Tier 2
€35 - €1,000
Tier 3
15
50
75
250
500
Tier 3
€15 - €500
Rules of engagement
Not applicable
Not applicable
max. 2 requests /sec
Not applicable

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Do not execute intrusive commands within production environments
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent also not POCs.

Validation times

We will always try to validate and accept your submissions as quickly as possible, for specific times you can check the average in the programme sidebar.

Domains

*.bild.de

Tier 1
Wildcard

Bild is the largest German tabloid newspaper.
Some examples of subdomains are

  • meinkonto.bild.de (user settings)
  • signin.auth.bild.de (login)
  • hey.bild.de (AI chat assistant)
  • angebot.bild.de (offers)
  • m.bild.de (mobile version)

You are also welcome to create your own account to test our system.

*.bild.tv

Tier 1
Wildcard

This is the livestream of the Bild television channel.

*.computerbild.de

Tier 1
Wildcard

Is a magazine with the topic computer from Bild.
Some examples of subdomains are

  • vip-club.computerbild.de (VIP club)
  • signin.auth.computerbild.de (login)

other interesting paths

  • computerbild.de/download (download center)

You are also welcome to create your own account to test our system.

*.welt.de

Tier 1
Wildcard

Large german broadsheet newspaper.
Some examples of subdomains are and areas

  • signin.auth.welt.de (login)
  • digital.welt.de (digital offers)
  • jobs.welt.de (job advertisements)
  • cancellation.prod.ps.welt.de (subscription cancelation)
  • epaper.welt.de

You are also welcome to create your own account to test our system.

18.184.198.198, 18.185.214.59, 18.194.109.179, 3.121.117.72, 3.121.138.10, 3.121.138.128, 3.121.138.134, 3.121.138.170, 3.121.138.33, 3.121.138.43, 3.124.248.208, 35.156.137.39

Tier 1
IP Range

IP addresses of our backend systems, comma separated.

https://dealer.prod.ps.axelspringer.de/purchases/004/bild/*

Tier 1
Wildcard

https://dealer.prod.ps.axelspringer.de/purchases/004/welt/*

Tier 1
Wildcard

*.autobild.de

Tier 2
Wildcard

Is a magazine with the topic cars from Bild.
Some examples of subdomains

  • club.autobild.de

You are also welcome to create your own account to test our system.

*.bz-berlin.de

Tier 2
Wildcard

Berlin based tabloid newspaper.
Some examples of subdomains

  • backend.bz-berlin.de

*.spring-media.de

Tier 2
Wildcard

Used for internal tools, mostly behind a VPN.

*.springtools.de

Tier 2
Wildcard

Used for internal tools, mostly behind a VPN.

URL

Used for internal tools, mostly behind a VPN.

*.ein-herz-fuer-kinder.de

Tier 3
Wildcard

Charity organisation for children in Germany.

*.fitbook.de

Tier 3
Wildcard

Magazine focusing on fitness topics.

*.myhomebook.de

Tier 3
Wildcard

Magazine focusing on home and garden topics.

*.petbook-magazine.com/

Tier 3
Wildcard

English version of the petbook.

*.petbook.de

Tier 3
Wildcard

Magazine focusing on pet topics.

*.stylebook.de

Tier 3
Wildcard

Magazine focusing on style topics.

*.techbook.de

Tier 3
Wildcard

Magazine focusing on tech topics.

*.travelbook.de

Tier 3
Wildcard

Magazine focusing on travel topics.

*.wissen-sie-mehr.de

Tier 3
Wildcard

Whistleblower form from BILD.

*.axelspringer.com

Out of scope
Wildcard
URL
In scope

Our worst-case scenarios are:

  • Publishing fake news on our website.
  • Obtaining sensitive user data.
  • Command execution on production services.
Out of scope

General

  • If a reported vulnerability is already known to the company, it will be marked as duplicate.
  • Vulnerabilities without realistic exploit scenario(s) or realistic attack surface(s) are assigned a severity of "None".
  • Spam, social engineering and physical intrusion are not allowed under any circumstances.
  • DoS/DDoS attacks or brute force attacks with more than 2 requests per second are not allowed.
  • Submissions based on software that no longer receives security updates will not be considered.
  • Attacks that require physical access to a victim's computer/device, man-in-the-middle or compromised user accounts are not permitted.
  • Zero day vulnerabilities are out of scope for the first 14 days following the release of a patch or mitigation.
  • Submissions without proof of concept will not be considered.
  • Multiple submissions based on the same piece of code, misconfiguration or dependency will be treated as a single submission. The deciding factor will be whether the problem can be fixed in one go.
  • All domains not listed as in scope above.

Application

  • Credential disclosure without proven business impact
  • Pre-Auth Account takeover/OAuth squatting
  • CORS misconfiguration on non-sensitive endpoints
  • Cross-site Request Forgery with no or low impact
  • Reverse tabnabbing
  • Clickjacking without proven impact/unrealistic user interaction
  • CSV Injection
  • Sessions not being invalidated (logout, enabling 2FA, etc.)
  • Tokens leaked to third parties
  • Anything related to email spoofing, SPF, DMARC or DKIM
  • Content injection without being able to modify the HTML
  • Username/email enumeration
  • Email bombing
  • Homograph attacks
  • XMLRPC enabled
  • Not stripping metadata of files
Severity assessment

This program follows Intigriti's contextual CVSS standard

FAQ

Do you have credentials to login into the applications?

No, we do not provide credentials for testing, but you are welcome to create your own account.

Can I give feedback to your program?

Yes certainly and we would appreciate use this feedback form for it.

Dos your program make use of retests?

Sometimes we will ask you to retest and offer up to a €50 bonus for doing so. If this offer is declined or expires and the submission is closed, we will not accept a submission with the same cause from the same researcher.

image.png
{180077} 3/6/2025, 1:57:46 PM
All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Overall stats
submissions received
1296
average payout
€219
accepted submissions
406
total payouts
N/A
Last 90 day response times
avg. time first response
< 2 days
avg. time to decide
< 1 week
avg. time to triage
< 3 days
Activity
3/27
logo
bughuntar
created a submission
3/27
Axel Springer SE
closed a submission
3/26
logo
cardcheat
created a submission
3/26
Axel Springer SE
closed a submission
3/26
Axel Springer SE
accepted a submission
3/26
Axel Springer SE
accepted a submission
3/26
Axel Springer SE
accepted a submission
3/26
Axel Springer SE
accepted a submission
3/26
Axel Springer SE
closed a submission
3/26
logo
moatasem12
created a submission