HackerOne · VDP

DIB-VDP Vulnerability Disclosure Program

Complete guide to DIB-VDP's vulnerability disclosure program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

DIB-VDP runs a vulnerability disclosure program on HackerOne. The program has 1029 in-scope assets.

1029
In-Scope Assets
13h
Avg Response
100%
Efficiency
240d
Avg Resolve

In-Scope Assets

AssetTypeMax SeverityEligible
38.142.101.156IP_ADDRESSCriticalNo Bounty
*.2asc.comWILDCARDCriticalNo Bounty
*.alex-as.comWILDCARDCriticalNo Bounty
*.alexamerican.comWILDCARDCriticalNo Bounty
*.americansystems.comWILDCARDCriticalNo Bounty
*.ascgov.comWILDCARDCriticalNo Bounty
*.ascsites.comWILDCARDCriticalNo Bounty
*.autodiscover.americansystems.comWILDCARDCriticalNo Bounty
*.coalfirefederal.comWILDCARDCriticalNo Bounty
*.ddlomni.comWILDCARDCriticalNo Bounty
*.dese.comWILDCARDCriticalNo Bounty
*.emsolve.comWILDCARDCriticalNo Bounty
*.epsilon-inc.comWILDCARDCriticalNo Bounty
*.epsilon-inc.devWILDCARDCriticalNo Bounty
*.hxfivelaunch.comWILDCARDCriticalNo Bounty
*.nhaero.comWILDCARDCriticalNo Bounty
*.savecloud.bizWILDCARDCriticalNo Bounty
*.savedev.bizWILDCARDCriticalNo Bounty
100.36.51.5IP_ADDRESSCriticalNo Bounty
104.249.144.8IP_ADDRESSCriticalNo Bounty
104.249.145.8IP_ADDRESSCriticalNo Bounty
12.125.144.150IP_ADDRESSCriticalNo Bounty
12.215.182.100IP_ADDRESSCriticalNo Bounty
12.96.87.210IP_ADDRESSCriticalNo Bounty
12.96.87.214IP_ADDRESSCriticalNo Bounty
12.96.87.216IP_ADDRESSCriticalNo Bounty
12.96.87.219IP_ADDRESSCriticalNo Bounty
129.222.249.89IP_ADDRESSCriticalNo Bounty
129.222.81.69IP_ADDRESSCriticalNo Bounty
13.64.181.40IP_ADDRESSCriticalNo Bounty
13.91.223.119IP_ADDRESSCriticalNo Bounty
132.228.146.2/32CIDRCriticalNo Bounty
132.228.191.97/32CIDRCriticalNo Bounty
132.228.24.17/32CIDRCriticalNo Bounty
132.228.45.35/32CIDRCriticalNo Bounty
134.223.117.169/32CIDRCriticalNo Bounty
134.223.117.170/32CIDRCriticalNo Bounty
134.223.117.197/32CIDRCriticalNo Bounty
134.223.117.198/32CIDRCriticalNo Bounty
134.223.120.148/32CIDRCriticalNo Bounty
134.223.120.152/32CIDRCriticalNo Bounty
134.223.120.154/32CIDRCriticalNo Bounty
134.223.120.166/32CIDRCriticalNo Bounty
134.223.120.167/32CIDRCriticalNo Bounty
134.223.120.169/32CIDRCriticalNo Bounty
134.223.120.180/32CIDRCriticalNo Bounty
134.223.120.183/32CIDRCriticalNo Bounty
134.223.120.184/32CIDRCriticalNo Bounty
134.223.120.186/32CIDRCriticalNo Bounty
134.223.120.33/32CIDRCriticalNo Bounty

Showing 50 of 1029 in-scope assets. View all on HackerOne.

Out-of-Scope Assets

  • http://adpass.bisimulations.com
  • http://bluechannel.bisimulations.com
  • http://cdc.bisimulations.com
  • http://cdc.devops.bisimulations.com
  • http://cdc.staging.bisimulations.com
  • http://cdc.staging.devops.bisimulations.com
  • http://cdcdevops.bisimulations.com
  • http://content.bisimulations.com
  • http://distribution-origin.bisimulations.com
  • http://dmz-cdnorigin1.bisimulations.com
  • http://ftp-au.bisimulations.com
  • http://ftp-orl.bisimulations.com
  • http://ftp-stage.terrasim.com
  • http://ftp.terrasim.com
  • http://kb.bisimulations.com
  • http://licensing.bisimulations.com
  • http://lm.bisimulations.com
  • http://manuals.bisimulations.com
  • http://marketplace.bisimulations.com
  • http://news.bisimulations.com

Tips for Hacking DIB-VDP

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking DIB-VDP?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does DIB-VDP pay bounties?

No, DIB-VDP runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.

What types of vulnerabilities does DIB-VDP accept?

DIB-VDP accepts reports for vulnerabilities found in their 1029 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.