Status DataClose notification
Bug bounty program

TTC | Mobile: Program info

TTC | Mobile

Company: TTC
Ended
Program left 4 years ago
Program infoHackers (10)Reports

TTC Connect, a lightweight wallet designed specifically for TTC, it was used to receive and send TTC safely and easily!

In scope
TargetTypeSeverity
TTC Connect Wallet
copy
Copy
success Copied

https://itunes.apple.com/us/app/ttc-connect-wallet/id1436822085?mt=8

iOS
Critical
TTC Connect
copy
Copy
success Copied

https://play.google.com/store/apps/details?id=com.ttc.wallet&hl=en_US

Android
Critical
TTC Connect APK
copy
Copy
success Copied

https://d1u6eqogwsdivn.cloudfront.net/apk/TTC_Connect.apk

Android
Critical
Target
TTC Connect Wallet
copy
Copy
success Copied

https://itunes.apple.com/us/app/ttc-connect-wallet/id1436822085?mt=8

TypeiOS
Severity
Critical
Target
TTC Connect
copy
Copy
success Copied

https://play.google.com/store/apps/details?id=com.ttc.wallet&hl=en_US

TypeAndroid
Severity
Critical
Target
TTC Connect APK
copy
Copy
success Copied

https://d1u6eqogwsdivn.cloudfront.net/apk/TTC_Connect.apk

TypeAndroid
Severity
Critical

Focus Area

In-Scope Vulnerabilities


We are interested in next vulnerabilities:

  • Remote code execution and stored XSS
  • Database vulnerability, SQLi
  • Privilege escalation (both vertical and horizontal)
  • Data breach
  • Authentication bypass
  • Obtaining sensitive information
  • IDOR/authorization vulnerabilities resulting in exposure of personal data.
  • Password attacks
  • Access to source code
  • Shell inclusion
  • Server Side Request Forgery (SSRF)
  • Remote code execution: e.g. through a maliciously-crafted web-site or an email
  • Local privilege escalation: e.g. situations when App allows a non-privileged user
  • Other application to gain Administrator or System rights

!Note: Current version of application operates over HTTP.

Program Rules

  • Avoid compromising any personal data, interruption or degradation of any service .
  • Don’t access or modify other user data, localize all tests to your accounts.
  • Don’t exploit any DoS/DDoS vulnerabilities, social engineering attacks or spam.
  • In case you find chain vulnerabilities we pay only for vulnerability with the highest severity.
  • Only the first valid bug is eligible for reward.
  • Don’t disclose publicly any vulnerability until you are granted permission to do so.
  • Don’t break any law and stay in the defined scope.
  • The existence or any details of this private program must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company.
  • Comply with the rules of the program.
  • The rewards will be paid out in HKN based on the current price.
Rewards
Range of bounty$250 - $5,000
Severity
Critical
$0
High
$0
Medium
$0
Low
$0
Stats
Scope Review467808
Submissions13
Total rewards$961
Types
apps
Hackers (10) View all
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response1d
Triage Time3d
Reward Time5d
Resolution Time7d