Twilio
Program Details
- Handle
- twilio
- Managed
- Yes
Response Metrics
- Response Time
- 5 days
- Bounty Time
- 57 days
- Resolution Time
- 4868 days
Scope (24 targets)
web: 13 mobile: 2 other: 9 In Scope
- *.sip.*.twilio.com web bounty-eligible
- Any host/web property verified to be owned by Twilio et al. other bounty-eligible
- Twilio APIs other bounty-eligible
- api.segment.io other bounty-eligible
- api.sendgrid.com web bounty-eligible
- api.twilio.com other bounty-eligible
- app.segment.com web bounty-eligible
- app.sendgrid.com web bounty-eligible
- http://help.twilio.com web bounty-eligible
- http://tsock.us1.twilio.com web bounty-eligible
- http://twilio.com/blog web bounty-eligible
- https://segment.com/docs/connections/sources/ web bounty-eligible
- https://www.authy.com/download/ mobile bounty-eligible
- https://www.authy.com/download/ mobile bounty-eligible
- https://www.twilio.com/docs/authy/api other bounty-eligible
- https://www.twilio.com/docs/libraries other bounty-eligible
- https://www.twilio.com/docs/verify/api other bounty-eligible
- https://www.twilio.com/en-us/blog/get-started-webrtc other bounty-eligible
- https://www.twilio.com/login?g=%2fconsole%3f&t=2b1c98334b25c1a785ef15b6556396290e3c704a9b57fc40687cbccd79c46a8c web bounty-eligible
- mc.sendgrid.com web bounty-eligible
- and 4 more targets
Out of Scope
All Kurento domains, All Twilio acquisitions until explicitly noted under the in-scope targets, Electric Imp and its assets, Third-party services, Twilio Quest, Twilio Wireless, TwimlBins, Ytica and its assets, community.segment.com, http://apjevents.twilio.com, http://events.cdpweek.com, http://segment.com/contact, http://segment.com/jobs, http://twilio.com/en-us/company/jobs, http://twilio.com/labs, jobs.twilio.com, lab.authy.com, signal.twilio.com, status.segment.com, status.sendgrid.com, status.twilio.com, store.twilio.com, support.sendgrid.com, support.twilio.com, surveys.twilio.com, talks.twilio.com, transform.twilio.com, twil.io, twiliotraining.com, webinars.segment.com, webinars.twilio.com, zipwhip.com
Known Exploited Vulnerabilities 1CVE
Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.
Additional Info
- Sources
- bugcrowd