Description

Lansweeper is an IT asset management software provider helping businesses better understand, manage and protect their IT devices and network. Lansweeper helps customers minimize risks and optimize their IT assets by providing actionable insight into their IT infrastructure at all times, offering trustworthy, valuable, and accurate insights about the state of users, devices, and software.

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
150
350
1,500
3,500
6,000
Tier 1
€150 - €6,000
Tier 2
100
250
750
1,500
2,500
Tier 2
€100 - €2,500
Tier 3
50
125
250
500
1,000
Tier 3
€50 - €1,000
Rules of engagement
Required
Not applicable
max. 5 requests /sec
Not applicable

Our promise to you

  • We will respond to reports as soon as possible
  • We are happy to respond to any questions, please use the button in the right top corner for this.

Your promise to us

  • Provide detailed but to-the point reproduction steps

  • Include a clear attack scenario. How will this affect us exactly?

  • Remember: quality over quantity!

  • Please do not discuss or post vulnerabilities without our consent (including PoC's on YouTube and Vimeo)

  • Please do not discuss or post metadata about vulnerabilities or the company name without our consent.

  • Please do not register public CVEs without our consent

  • Please do not use automatic scanners -be creative and do it yourself! We cannot accept any submissions found by using automatic scanners. Scanners also won't improve your skills, and can cause a high server load (we'd like to put our time in thanking researchers rather than blocking their IP's 😉)

  • The usage of Lansweeper licenses is only to be used for the purpose of ethical hacking, and not to manage your own IT estate.

Domains

Domain used during the two-way sync process between the local web console (on-premises software) and the cloud platform.

You can request your trial on our website: https://www.lansweeper.com/download/ but always use "intigriti.me" address for any user account

With this trial you get access to our cloud platform (app.lansweeper.com), our on-premises software and the sync process (edge.lansweeper.com) between these two. You have to install our on-premises software somewhere locally and this will allow you to scan your local network and push the results to the cloud platform via the sync process.

API used for integrations with our cloud platform (app.lansweeper.com).
More information about our API: https://docs.lansweeper.com/docs

The cloud Platform, this also includes lecstaticcontent.lansweeper.com

You can request your trial on our website: https://www.lansweeper.com/download/ but always use "intigriti.me" address for any user account

With this trial you get access to our cloud platform (app.lansweeper.com), our on-premises software and the sync process (edge.lansweeper.com) between these two. You have to install our on-premises software somewhere locally and this will allow you to scan your local network and push the results to the cloud platform via the sync process.

Severity assessment

This program follows Intigriti's contextualised cvss standard

FAQ

Where can we get credentials for the cloud application?

You can self-register on the cloud application but please don’t forget to use your @intigriti.me address

How can I install the local Lansweeper installation?

You can download the installation right away from your trial (https://www.lansweeper.com/download/)

Where can we get a license key for the on-premise software?

You can request your trial on our website: https://www.lansweeper.com/download/ but always use "intigriti.me" address for any user account

Where can I get more information about the functionality of the applications?

https://www.lansweeper.com/cloud-platform/adp-onboarding-webinar/
https://vimeo.com/478464790/6dc99939b3 (set-up and synchronize assets)
https://www.lansweeper.com/kb-category/api/index.html
https://www.lansweeper.com/kb (mainly for on-prem software)

What is a site and an installation in the cloud applications?

When registering on the cloud application, you can create your own site(s) for your personal use, and add local Lansweeper installations (multiple are possible) to this site. Adding a local Lansweeper installation is explained in the ADP onboarding webinar (see above).

How can I use a different email address than "intrigiti.me" to test certain features such as SSO?

If you need to use an email address with a domain other than "intigriti.me" you must contact support explaining the reasons for using a different email address and the new one to use.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.