/engagements/t-mobile

BugcrowdView on Bugcrowd
RawAI Enhanced
51
In Scope
6
Out of Scope

In-Scope Assets (51)

AssetCategoryBountyQuick Links
Assets labeled as in-scopeOTHERYes-
Cellular Network Auth Bypass via Web/Mobile AppOTHERYes-
Internal Server via Internet NetworkOTHERYes-
Self Register Account on T-Mobile Microsoft Entra IDOTHERYes-
T&P ServersOTHERYes-
https://*.assurancewireless.comURLYes
https://*.uscc.comURLYes
https://*.uscc.netURLYes
https://*.uscellular.comURLYes
https://account.t-mobile.comURLYes
https://api.t-mobile.comURLYes
https://api.vistarmedia.comURLYes
https://api.vistarmedia.euURLYes
https://apps.apple.com/us/app/syncup-drive/id1576574297IOSYes-
https://apps.apple.com/us/app/syncup-kids/id1503394062IOSYes-
https://apps.apple.com/us/app/syncup-tracker/id1526380335IOSYes-
https://apps.apple.com/us/app/t-life-t-mobile-tuesdays/id1111876388IOSYes-
https://apps.apple.com/us/app/t-mobile/id561625752IOSYes-
https://assets-cdn.vistarmedia.comURLYes
https://audience-builder.vistarmedia.comURLYes
https://clients.adstruc.comURLYes
https://creatives.vistarmedia.comURLYes
https://dashboard-101.moengage.comURLYes
https://demo.adstruc.comURLYes
https://devedge.t-mobile.comURLYes
https://digits.t-mobile.comURLYes
https://digits.t-mobile.com/OTHERYes-
https://docker-staging.adstruc.comURLYes
https://docsite.vistarmedia.comURLYes
https://job-svc-b.vistarmedia.comURLYes
https://maps.vistarmedia.comURLYes
https://metrobyt-mobile.comURLYes
https://packages.cortexpowered.comURLYes
https://play.google.com/store/apps/details?id=com.tmobile.driveANDROIDYes
https://play.google.com/store/apps/details?id=com.tmobile.kidsANDROIDYes
https://play.google.com/store/apps/details?id=com.tmobile.pr.mytmobileANDROIDYes
https://play.google.com/store/apps/details?id=com.tmobile.syncuptagANDROIDYes
https://play.google.com/store/apps/details?id=com.tmobile.tuesdays&hl=en_US&gl=USANDROIDYes
https://production-delivery-metrics-svc.vistarmedia.comURLYes
https://production-dynam-creative.vistarmedia.comURLYes
https://sfleet.cortexpowered.comURLYes
https://sflower.cortexpowered.comURLYes
https://sprint.comURLYes
https://staging-login.vistarmedia.comURLYes
https://staging-trafficking.vistarmedia.comURLYes
https://storybook.vistarmedia.comURLYes
https://t-mobile.comURLYes
https://tess.service-now.comURLYes
https://tfb.t-mobile.comURLYes
https://transcodes-cdn.vistarmedia.comURLYes
https://www.assurancewireless.comURLYes
Out-of-Scope Assets (6)
AssetCategoryBounty
*.mobile.uscc.comURLYes
*.mobile.uscc.netURLYes
*.sprint.netURLYes
/self-service-*URLYes
Any domain, property, product, protocol, or service of the app/hardware/software version not explicitly listed in the In-Scope section is out of scope; submissions are welcome but not guaranteed for the bounty/bonus.OTHERYes
https://*.moengage.comURLYes