Posten Bring AS is a Nordic postal and logistics group that develops and delivers comprehensive solutions within post and logistics. We have over 12,600 employees, and meet the market with the two brands Posten and Bring.
This is a responsible disclosure program without bounties.
While we do not offer bounties for reported vulnerabilities, we deeply appreciate your contribution to securing our systems. As a token of our gratitude, we offer invites to private bug bounty programs in specific cases, such as high severity vulnerabilities and well written reports.
By participating in this program, you agree to:
- Only use publicly available test environments for testing (see below) to avoid impacting production
- Respect the Community Code of Conduct
- Respect the Intigriti Terms and Conditions
- Respect the scope of the program
- Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)
Test environments
- difitest.digipost.no
- difitest.signering.posten.no
This Responsible Disclosure Program covers all Posten Bring AS services. Researchers should perform testing against the test environments listed in the Rules of engagement section to avoid impacting production.
Any system not explicitly listed in the in-scope section or third-party services not owned or managed by Posten Bring is out of scope.
General
- Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited
- Spam, social engineering and physical intrusion
- DoS/DDoS attacks or brute force attacks
- Vulnerabilities that only work on software that no longer receive security updates
- Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts
- Recently discovered zero-day vulnerabilities found in in-scope assets within 14 days after the public release of a patch or mitigation may be reported, but are usually not eligible for a bounty
- Reports that state that software is out of date/vulnerable without a proof-of-concept
Application
- Pre-Auth Account takeover/OAuth squatting
- Self-XSS that can't be used to exploit other users
- Verbose messages/files/directory listings without disclosing any sensitive information
- CORS misconfiguration on non-sensitive endpoints
- Missing cookie flags
- Missing security headers
- Cross-site Request Forgery with no or low impact
- Presence of autocomplete attribute on web forms
- Reverse tabnabbing
- Bypassing rate-limits or the non-existence of rate-limits.
- Best practices violations (password complexity, expiration, re-use, etc.)
- Clickjacking without proven impact/unrealistic user interaction
- CSV Injection
- Sessions not being invalidated (logout, enabling 2FA, etc.)
- Content injection without being able to modify the HTML
- Email bombing
- HTTP Request smuggling without any proven impact
- Homograph attacks
- Banner grabbing/Version disclosure
- Not stripping metadata of files
- Arbitrary file upload without proof of the existence of the uploaded file
- Host header injection without proven business impact
Mobile
- Shared links leaked through the system clipboard
- Any URIs leaked because a malicious app has permission to view URIs opened
- The absence of certificate pinning
- Sensitive data in URLs/request bodies when protected by TLS
- Lack of obfuscation
- Path disclosure in the binary
- Lack of jailbreak & root detection
- Crashes due to malformed URL Schemes
- Lack of binary protection (anti-debugging) controls
- Snapshot/Pasteboard leakage
- Runtime hacking exploits (exploits only possible in a jailbroken environment)
- API key leakage used for insensitive activities/actions
This program follows Intigriti's triage standards based on the proof of concept.
Where can we get credentials for the applications?
The process will vary depending on the application. Some applications allow you to self-register while others use Norwegian ID-solutions or require invitations.
Digipost
Norwegian ID is required in production, but you can self-register in the difitest environment.
Personal account
- Go to https://www.difitest.digipost.no/registrering/en/person
- Click "Continue"
- Choose "TestID"
- Click "Find random user" and save the SSN (you need it when logging in again)
- Click "Authenticate"
- Enter your @intigriti.me email address and any phone number
- Click "Create Digipost account"
- Skip phone number verification by clicking "Continue without confirming now"
- Complete the registration process
To log in next time go to https://www.difitest.digipost.no/innlogging/en, select TestID and enter the SSN.
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.






























