Scope Updates

Recent changes to bug bounty program scopes.

ChangeAssetCategoryScopeProgramPlatformTime
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedanything that is not explicitely listed in scope sectionOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedhttps://www.cybermalveillance.gouv.frOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedplease note that some of the applications may contain links or redirect you away from the uris described in the scope section. this means you are leaving the scope if you follow these links / redirectsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany services related to incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedthe alternative login (https://login.swissid.ch) is out of scope. it also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedattacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes dns, ntp, routers, systems of the isp, etc.)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedanything that has not been described as in scope in the previous section is automatically out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedthird parties such as security researchers already involved in active security audits, or already opened reportsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedlibraries and protocols with known limitations and gems already in update maintenance (e.g., omniauth < 2 csrf protections, carrierwave)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeddevelopment configurations, plugins or images, such as the development or all-in-one docker containers, or running application in non-production modes and configurationsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedvulnerabilities in the dns protocol that are not specific to the bind 9 implementation (while we are interested in these, they are out of scope of this bug bounty program)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany third parties’ or community’s assets (e.g. packages or versions not created and published by isc)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedlists.isc.orgOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedgitlab.isc.orgOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.retarus.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.gdata.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.usersnap.comOTHEROut of ScopeYesWeHack2026-02-21 00:33