netflix
30
In Scope
9
Out of Scope
In-Scope Assets (30)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.nflxext.com | WILDCARD | Yes | ||
| *.nflximg.net | WILDCARD | Yes | ||
| *.nflxso.net | WILDCARD | Yes | ||
| *.nflxvideo.net | WILDCARD | Yes | ||
| *.prod.cloud.netflix.com | WILDCARD | Yes | ||
| *.prod.dradis.netflix.com | WILDCARD | Yes | ||
| *.prod.ftl.netflix.com | WILDCARD | Yes | ||
| Affiliates or entities such as recently acquired companies | OTHER | No | - | |
| Content Authorization Targets | OTHER | Yes | - | |
| Content authorization vulnerabilities affecting only the in-browser player | OTHER | No | - | |
| Corporate Assets | OTHER | Yes | - | |
| Low impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Drive Links” in the “Corporate Targets” section) | OTHER | No | - | |
| Microsites | OTHER | Yes | - | |
| Netflix Gaming Target | OTHER | No | - | |
| Netflix Mobile Application for Android | ANDROID | Yes | - | |
| Netflix Mobile Application for iOS | IOS | Yes | - | |
| Open Source - Atlas | CODE | Yes | - | |
| Open Source - Spectator | OTHER | Yes | - | |
| Open Source - Zuul | OTHER | Yes | - | |
| Secondary Assets | OTHER | Yes | - | |
| api*.netflix.com | WILDCARD | Yes | ||
| beacon.netflix.com | URL | Yes | ||
| customerevents.netflix.com | URL | Yes | ||
| help.netflix.com | URL | Yes | ||
| ichnaea.netflix.com | URL | Yes | ||
| meechum.netflix.com | URL | Yes | ||
| nmtracking.netflix.com | URL | Yes | ||
| presentationtracking.netflix.com | URL | Yes | ||
| secure.netflix.com | URL | Yes | ||
| www.netflix.com | URL | Yes |
Out-of-Scope Assets (9)
| Asset | Category | Bounty | |
|---|---|---|---|
| Assets associated with ReadyPlayerMe | OTHER | No | |
| Open Source - Consoleme | OTHER | No | |
| Open Source - Dispatch | OTHER | No | |
| Open Source - Weep | OTHER | No | |
| Set-top-boxes, smart TVs, streaming sticks Out of Scope | OTHER | No | |
| Third party websites or systems hosted by non-Netflix entities Out of Scope | OTHER | No | |
| ir.netflix.com | URL | No | |
| ir.netflix.net | URL | No | |
| netflixinvestor.com | URL | No |