Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

t-mobile

BugcrowdView on Bugcrowd
RawAI Enhanced
51
In Scope
8
Out of Scope

In-Scope Assets (51)

AssetCategoryBountyQuick Links
Assets labeled as in-scopeOTHERNo-
Cellular Network Auth Bypass via Web/Mobile AppOTHERNo-
Internal Server via Internet NetworkOTHERNo-
Self Register Account on T-Mobile Microsoft Entra IDOTHERNo-
T&P ServersOTHERNo-
https://*.uscc.comURLNo
https://*.uscc.netURLNo
https://*.uscellular.comURLNo
https://account.t-mobile.comURLNo
https://api.t-mobile.comURLNo
https://api.vistarmedia.comURLNo
https://api.vistarmedia.euURLNo
https://apps.apple.com/us/app/syncup-drive/id1576574297IOSNo-
https://apps.apple.com/us/app/syncup-kids/id1503394062IOSNo-
https://apps.apple.com/us/app/syncup-tracker/id1526380335IOSNo-
https://apps.apple.com/us/app/t-life-t-mobile-tuesdays/id1111876388IOSNo-
https://apps.apple.com/us/app/t-mobile/id561625752IOSNo-
https://assets-cdn.vistarmedia.comURLNo
https://audience-builder.vistarmedia.comURLNo
https://clients.adstruc.comURLNo
https://creatives.vistarmedia.comURLNo
https://dashboard-04.moengage.comURLNo
https://demo.adstruc.comURLNo
https://devedge.t-mobile.comURLNo
https://digits.t-mobile.comURLNo
https://digits.t-mobile.com/OTHERNo-
https://docker-staging.adstruc.comURLNo
https://docsite.vistarmedia.comURLNo
https://job-svc-b.vistarmedia.comURLNo
https://maps.vistarmedia.comURLNo
https://metrobyt-mobile.comURLNo
https://packages.cortexpowered.comURLNo
https://play.google.com/store/apps/details?id=com.tmobile.driveANDROIDNo
https://play.google.com/store/apps/details?id=com.tmobile.kidsANDROIDNo
https://play.google.com/store/apps/details?id=com.tmobile.pr.mytmobileANDROIDNo
https://play.google.com/store/apps/details?id=com.tmobile.syncuptagANDROIDNo
https://play.google.com/store/apps/details?id=com.tmobile.tuesdays&hl=en_US&gl=USANDROIDNo
https://portal.lrs.t-mobile.comURLNo
https://production-delivery-metrics-svc.vistarmedia.comURLNo
https://production-dynam-creative.vistarmedia.comURLNo
https://sfleet.cortexpowered.comURLNo
https://sflower.cortexpowered.comURLNo
https://sprint.comURLNo
https://staging-login.vistarmedia.comURLNo
https://staging-trafficking.vistarmedia.comURLNo
https://storybook.vistarmedia.comURLNo
https://t-mobile.comURLNo
https://tess.service-now.comURLNo
https://tfb.t-mobile.comURLNo
https://transcodes-cdn.vistarmedia.comURLNo
https://www.assurancewireless.comURLNo
Out-of-Scope Assets (8)
AssetCategoryBounty
*.mobile.uscc.comURLNo
*.mobile.uscc.netURLNo
*.sprint.netURLNo
/self-service-*URLNo
Any domain, property, product, protocol, or service of the app/hardware/software version not explicitly listed in the In-Scope section is out of scope; submissions are welcome but not guaranteed for the bounty/bonus.OTHERNo
eventmanager.uscellular.comURLNo
events.eventmanager.uscellular.comURLNo
global.eventmanager.uscellular.comURLNo