Adobe Live Hacking Event

Hack 4 Adobe: Calling All Security Researchers

Are you ready to showcase your skills, collaborate with fellow experts, and help secure the digital experience of millions around the globe? Adobe is inviting talented security researchers at DefCamp to participate in an exciting live hacking event, where you’ll have the opportunity to identify real vulnerabilities, earn rewards, and contribute to securing Adobe’s products.

The event kicks off online on November 25th, and will culminate on November 29th during the conference, where a special prize for the researcher submitting the best vulnerability report will be awarded.

How to Participate: To take part, you must create a HackerOne account and submit all reports through Adobe’s Public Bug Bounty program. Sign up at: hackerone.com/adobe.

Ready to make an impact?

Rules of engagement:
  • Please use your own account for testing or research purposes. Do not attempt to gain access to another user’s account or confidential information.
  • Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.
  • Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
  • When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced).
  • Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
  • Please do not test for spam, social engineering, or denial of service issues.
  • Please do not engage in any activity that can potentially or actually cause harm to Adobe, our customers, or our employees.
  • Do not engage in any activity that violates (a) federal or state laws or regulations or (b) the laws or regulations of any country where (i) data, assets, or systems reside, (ii) data traffic is routed, or (iii) the researcher is conducting research activity.
  • Do not store, share, compromise, or destroy Adobe or customer data. If Personally Identifiable Information (PII) is encountered, you should immediately halt your activity, purge related data from your system, and immediately contact Adobe. This step protects any potentially vulnerable data, and you.

Some vulnerabilities are out of scope for the live hacking event. Please review the full list in the “Program exclusions” section of the policy page – https://hackerone.com/adobe?type=team#user-content-program-exclusions along with the testing plan for each product in scope before submitting any reports.

Prizes / Rewards

SeverityUSD
Critical$ 2500 – $ 5000
High$ 500 – $ 2500
Medium$ 100 – $ 500
Low$ 100

Submit your bug report with code: ADOBELOVESDEFCAMP24 (Code expires January 31, 2025) to earn an additional 10% bounty on your bug reports against Photoshop Web or Identity Management Services (IMS).

At the end of DefCamp on November 29, 2024  at 5PM, Palace of the Parliament in Bucharest, we will award a 1-year Creative Cloud subscription to the researcher who has submitted the best vulnerability against Identity Management Services (IMS) and/or Photoshop Web. 

NO PUR. NEC. Enter by Nov 29, 2024. Must be 18+ and a registered attendee of DefCamp 2024. For complete details and prize descriptions see Official Rules. Void where prohibited. Originator: Adobe.

Every valid report will earn Hall of Fame points: https://helpx.adobe.com/security/security-researcher-hall-of-fame.html

SPONSORED BY