Scope Updates

Recent changes to bug bounty program scopes.

ChangeAssetCategoryScopeProgramPlatformTime
Addedall domains not listed in scopes, noteworthy:OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedalasco will not provide access credentials to any system, not for testing and also not for issue validationOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedhowever, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this programOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedplease note that all non-authenticated areas of our systems are in scope for this program. this means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a rewardOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedalasco.deOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedwww.alasco.deOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedexplore.alasco.deOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedexplore.alasco.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall other domains or subdomains not listed in the above list of 'scopes'OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedeverything that is not directly related to the application or source-code in scope (e.g. github, domain settings)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Added"scopes" in this program refer to the binary packages and source-code provided there, the systems providing those artefacts are out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall content which is not listed as "scopes", especially any production system operated by customersOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedsecurity concerns originating from https://moneyboxapp.onelogin.com/ are typically considered out of scope. these pages and their content are served by onelogin, and any issues should be reported to them directly. however, if an exploit explicitly enables bypassing onelogin to access moneybox systems or leaking moneybox sensitive data, it is crucial to raise the concerns to both onelogin and moneyboxOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedcontent served by the cloudflare access service (https://moneyboxapp.cloudflareaccess.com/*) is out of scope. these pages intentionally do not set a cors allow-origin policy. we have seen this reported several times as a vulnerability, but it is intended behaviour and is considered out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedthe moneybox public website https://www.moneyboxapp.com/ and other moneyboxapp.com / moneyboxapp.org domains not listed are out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedthe sncf connect mobile applications (android and apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff')OTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- https://www.malocationavis.sncf-connect.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- https://www.maxjeune-tgvinoui.sncfOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- https://www.sncf-voyageurs.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- https://tgvinoui.sncfOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- https://www.sncf.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedanything that is not listed as part of the scope, example :OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedplease note sncf-connect.com doesn't own the sncf.com domainsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedplease note that tchap is hosted by a third party and thus vulnerabilities related to the host are out of the scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedeverything that not listed as in scope is to be considered as out of scope of this programOTHEROut of ScopeYesWeHack2026-02-21 00:33