Scope Updates

Recent changes to bug bounty program scopes.

ChangeAssetCategoryScopeProgramPlatformTime
Addedany asset that is not explicitly included in our program's scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedother business units of the telenor group - including *.telenor.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedtelenor idOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedmobile services and devices provided by telenor sweden and subsidiaries not reachable from internetOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany domain that looks like it's owned by a third party or customer due customer's privacyOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedstage-vimla-se.vimla.ioOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.cust.ownit.seOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.customers.ownit.seOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.cust.bredbandsbolaget.seOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.sme.telenor.seOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.cust.telenor.seOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added*.bbcust.telenor.seOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeddatabase service instances from customers, like *.dbaas.infomaniak.cloudOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeds3 credentials from our customers, like s3.pub*.infomaniak.cloudOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedwebsocket ips-public credentials. public identifiers that do not allow access to information outside the scope of the user's profileOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addeduser email verificationOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedmysql credentials from our customers, like *.myd.infomaniak.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedvps instances from our customers, like *.vps.infomaniak.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedftp credentials from our customers, like *.ftp.infomaniak.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedthis domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. this is only office application, an external app to open ms office documentsOTHEROut of ScopeYesWeHack2026-02-21 00:33