< NULLCON 2025 - GOA />

Live Bug Hunting

LIVE

Live Bug Hunting at Nullcon Goa 2025

Challenge yourself and be rewarded by our partners, who are here to engage with the community. Third year in a row Nullcon is organizing its live private bug bounty program for our conference attendees. We encourage responsible disclosure, foster open conversation and help our partners built trust/ relationship with the hacker community.

Venue & Date:

28th Feb - 2nd March BITS Pilani, Goa

Time:

10:30 am to 4:30 pm

Targets: Adobe | Airtel Business

*Limited seats to only registered conference attendees. If you are interested to get the invite for this private event, then fill up the form below. Kindly note, only 100 candidates would be selected for this Live Bug Hunting


Are you ready to showcase your skills, collaborate with fellow experts, and help secure the digital experience of millions around the globe? Adobe is inviting talented security researchers at NullCon to participate in an exciting live bug bounty event, where you’ll have the opportunity to identify real vulnerabilities, earn rewards, and contribute to securing Adobe’s products.

The event kicks off online on February 28, 1 day before NullCon and will culminate on March 2 during the conference, where special prizes will be awarded. See prize details below.

How to Participate:To take part, you must create a HackerOne account and submit all reports through Adobe’s Bug Bounty program.

Scope:

PLEASE READ: Some vulnerabilities are out of scope for the live hacking event. Please review the full list in the “Program exclusions” section of the policy page along with the testing plan for each product in scope before submitting any reports.

Rewards:

Product Low
(0.1 - 3.9)
Medium
(4.0 - 6.9)
High
(7.0 - 8.9)
Critical
(9.0 - 10.0)
ColdFusion $100 - $200 $200 - $1,000 $1,000 - $5,000 $5,000 - $10,000
Learning Manager $100 $100 - $500 $500 - $2,500 $2,500 - $5,000

Submit your bug report with code: NULLCONLIVE2025 (Code expires March 3, 2025) to earn an additional 10% bounty on your bug reports against Adobe Learning Manager or ColdFusion.

At the end of NullCon on March 2, Adobe will award two prizes to TWO winners:

  • AirPods Pro 2 to the researcher who has submitted the “best vulnerability” during the live bug bounty event, and
  • A 1-year Creative Cloud Subscription to the researcher who has submitted the “most creative vulnerability” during the live bug bounty event.

Every valid report will earn Hall of Fame points https://helpx.adobe.com/security/security-researcher-hall-of-fame.html

“See more details of the competition rules here: https://acrobat.adobe.com/id/urn:aaid:sc:VA6C2:1df8f1ba-dd73-4dc4-818e-d4be77736737”



Rules of Engagement

  • Please use your own account for testing or research purposes. Do not attempt to gain access to another user’s account or confidential information.
  • Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.
  • Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
  • When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced).
  • Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.
  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
  • Please do not test for spam, social engineering, or denial of service issues.
  • Please do not engage in any activity that can potentially or actually cause harm to Adobe, our customers, or our employees.
  • Do not engage in any activity that violates (a) federal or state laws or regulations or (b) the laws or regulations of any country where (i) data, assets, or systems reside, (ii) data traffic is routed, or (iii) the researcher is conducting research activity.
  • Do not store, share, compromise, or destroy Adobe or customer data. If Personally Identifiable Information (PII) is encountered, you should immediately halt your activity, purge related data from your system, and immediately contact Adobe. This step protects any potentially vulnerable data, and you

Scope:

Web app, mobile app as well as IOT devices. Actual domains/apps/devices to be disclosed on 28th Feb. The rules of engagement and exclusions will be disclosed 2 days prior to selected security researchers only.


Total Bounty worth ₹10,00,000!!
with up to ₹ 60,000 for critical severity bug!!

The reward amount will be based on the severity of the bug report and the severity will be decided based on business, financial, and reputational impact along with combination of CVSS rating for technical impact.

This will be verified by the Airtel team and post validation; rewards will be given to the researchers. The bounty amount will be awarded to the researcher within 30 days.




Registration

Signing NDA

Explaining Do's
and Dont's

Reporting Bug

Validation
of Bugs

Rewards




Bug Submission

All bug submissions to be done at https://securitybugs.airtel.in/ during the event only, no prior and later submissions will be considered.



Rules of Engagement

  • This event is only for the registered Conference Attendees from India. If you haven’t registered yet, then grab your tickets here - Nullcon Security Conference & Training
  • You will also be required to fill in an NDA, to not disclose any bug in public or via blog/article/presentation until the bug has been fixed by Airtel or taken prior approval from the Airtel team.