Program Removed

This program is no longer available on YesWeHack. The scope data shown below is historical and may not reflect the final state of the program.

bind-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
3
In Scope
26
Out of Scope
In-Scope Assets (3)
AssetCategoryBountyQuick Links
https://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEYes-
https://gitlab.isc.org/isc-projects/bind9URLYes
https://gitlab.isc.org/isc-projects/bind9CODEYes-
Out-of-Scope Assets (26)
AssetCategoryBounty
- any asset that is not explicitly included in our program's scopeOTHERYes
- any deprecated versions and versions other than the current stable/official versionOTHERYes
- any local implementation of the project/implementation belonging to third partiesOTHERYes
- any third parties' or community assets (e.g. packages or versions not created and published by isc)OTHERYes
- any vulnerability that requires admin or admin-like access (see above for more details) — this includes access to files on disk, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk, and authenticated access to change the zone file contents (zone transfers, dns update)OTHERYes
- gitlab.isc.orgOTHERYes
- lists.isc.orgOTHERYes
- vulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHERYes
any asset that is not explicitly included in our program's scopeOTHERYes
any asset that is not explicitly included in our program's scopeOTHERYes
any deprecated versions and versions other than the current stable/official versionOTHERYes
any depreciated versions and other versions than the current stable/official version are considered out of scopeOTHERYes
any local implementation of the project/implementation belonging to third partiesOTHERYes
any local implementation of the project/implementation belonging to third partiesOTHERYes
any third parties' or community assets (e.g. packages or versions not created and published by isc)OTHERYes
any third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHERYes
any vulnerability that requires admin or admin-like access (see above for more details) — this includes access to files on disk, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk, and authenticated access to change the zone file contents (zone transfers, dns update)OTHERYes
any vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update)OTHERYes
gitlab.isc.orgOTHERYes
gitlab.isc.orgOTHERNo
gitlab.isc.orgURLYes
lists.isc.orgURLYes
lists.isc.orgOTHERNo
lists.isc.orgOTHERYes
vulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHERYes
vulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHERYes
Scope Changes (63)
Aug 27, 2026
ChangeAssetCategoryScopeTime
Program Removed18:47
Aug 12, 2026
ChangeAssetCategoryScopeTime
Added- any local implementation of the project/implementation belonging to third partiesOTHEROut of Scope10:47
Addedhttps://gitlab.isc.org/isc-projects/bind9CODEIn Scope10:47
Added- lists.isc.orgOTHEROut of Scope10:47
Added- any asset that is not explicitly included in our program's scopeOTHEROut of Scope10:47
Added- vulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope10:47
Added- any vulnerability that requires admin or admin-like access (see above for more details) — this includes access to files on disk, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk, and authenticated access to change the zone file contents (zone transfers, dns update)OTHEROut of Scope10:47
Addedhttps://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEIn Scope10:47
Added- gitlab.isc.orgOTHEROut of Scope10:47
Added- lists.isc.orgOTHEROut of Scope10:47
Added- any asset that is not explicitly included in our program's scopeOTHEROut of Scope10:47
Added- any third parties' or community assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope10:47
Added- any deprecated versions and versions other than the current stable/official versionOTHEROut of Scope10:47
Added- any local implementation of the project/implementation belonging to third partiesOTHEROut of Scope10:47
Added- vulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope10:47
Added- any vulnerability that requires admin or admin-like access (see above for more details) — this includes access to files on disk, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk, and authenticated access to change the zone file contents (zone transfers, dns update)OTHEROut of Scope10:47
Added- gitlab.isc.orgOTHEROut of Scope10:47
Added- any deprecated versions and versions other than the current stable/official versionOTHEROut of Scope10:47
Added- any third parties' or community assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope10:47
Apr 10, 2026
ChangeAssetCategoryScopeTime
Program Removed14:21
Apr 7, 2026
ChangeAssetCategoryScopeTime
Addedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope08:21
Removedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope08:21
Addedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope07:21
Addedany vulnerability that requires admin or admin-like access (see below for more details) - this includes access to files on drive, administrative interfaces (rndc, statistics channel), access to any shared key, privileges to write files on disk and authenticated access to change the zone file contents (zone transfers, dns update).OTHEROut of Scope07:21
Mar 26, 2026
ChangeAssetCategoryScopeTime
Removedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope16:06
Removedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope16:06
Removedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope16:06
Removedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope16:06
Removedhttps://gitlab.isc.org/isc-projects/bind9URLIn Scope16:06
Removedgitlab.isc.orgURLOut of Scope16:06
Removedlists.isc.orgURLOut of Scope16:06
Removedany asset that is not explicitly included in our program's scopeOTHEROut of Scope16:06
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope19:08
Addedhttps://gitlab.isc.org/isc-projects/bind9URLIn Scope19:08
Addedgitlab.isc.orgURLOut of Scope19:08
Addedlists.isc.orgURLOut of Scope19:08
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope19:08
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope19:08
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope19:08
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:51
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope00:51
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope00:51
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:51
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope00:51
Addedhttps://gitlab.isc.org/isc-projects/bind9CODEIn Scope00:51
Addedgitlab.isc.orgURLOut of Scope00:51
Addedlists.isc.orgURLOut of Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedhttps://gitlab.isc.org/isc-projects/bind9OPEN-SOURCEIn Scope21:40
Removedgitlab.isc.orgOTHEROut of Scope21:40
Removedlists.isc.orgOTHEROut of Scope21:40
Removedany asset that is not explicitly included in our program's scopeOTHEROut of Scope21:40
Removedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope21:40
Removedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope21:40
Removedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope21:40
Removedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope21:40
Addedgitlab.isc.orgOTHEROut of Scope00:33
Addedlists.isc.orgOTHEROut of Scope00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of Scope00:33
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of Scope00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of Scope00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of Scope00:33
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of Scope00:33