Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

british_airways_vdp

HackerOneView on HackerOne
RawAI Enhanced
5
In Scope
3
Out of Scope

In-Scope Assets (5)

AssetCategoryBountyQuick Links
*.ba.comWILDCARDNo
*.britishairways.comWILDCARDNo
Security vulnerabilities that are identified in digital properties owned, operated, or controlled by British Airways are considered in scope.OTHERNo-
http://www.britishairways.com/nxURLNo
www.britishairways.comURLNo
Out-of-Scope Assets (3)
AssetCategoryBounty
Testing is not permitted on internal systems, employee portals, onboard aircraft systems, third-party services, or any assets using external networks or domains not directly owned or controlled by British AirwaysOTHERNo
accounts.britishairways.comURLNo
holiday.britishairways.comURLNo