— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for S-Pankki.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 0,
"average_time_to_first_program_response": 4,
"average_time_to_report_resolved": 2169,
"handle": "s-pankki",
"id": 0,
"managed_program": true,
"name": "S-Pankki",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 83,
"submission_state": "open",
"url": "https://hackerone.com/s-pankki",
"website": "https://www.s-pankki.fi",
"targets": {
"in_scope": [
{
"asset_identifier": "740514933",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-mobiili banking application (iOS).\n\nThe application can be found from App Store \nhttps://apps.apple.com/fi/app/s-mobiili/id740514933?l=fi\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "digili.s-cloud.fi",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Services for S-Bank and S-group customers where customers can take S-bank basic banking services into use (later \"digipa\") and gain S-Group co-op membership (later \"digili). \n\nBasic banking services include opening an account and setting it as a benefit services account, applying for Visa Debit-card and opening and ordering net bank credentials that can be used as logging into S-bank netbank and using credentials to identify oneself in digital environments.\n\nDigili and Digipa are different applications but they are built on top of same services. Difference Between Digili and Digipa is that in Digili user opens S-group co-op membership before opening basic banking services. In Digipa user can open banking services directly without the need to gain S-group co-op membership. In case user doesn’t have required co-op membership s/he is directed to Digili application.\n\nIf user has already co-op membership and s/he enters Digili, user will be forwarded to open banking services. In case user has some of the offered basic banking services in use, the step is skipped and user is shown a possibility to open the missing services.\n\nDigili and Digipa applications can be entered through https://www.s-pankki.fi/fi/tule-asiakkaaksi/, https://www.s-kanava.fi/asiakaspalvelu/nain-liityt/ or taking S-mobiili into use as a non- S-group co-op member where user is directed automatically to Digili to gain S-group co-op membership that is a requirement to take S-mobiili into use.\n\nIn order to access Digili or Digipa user needs to be able to authenticate himself/hersef with Finnish banking credentials or through Mobiilivarmenne.\nUser need also to fulfill following requirements in order to be able to access the service:\n- Needs to be 18 years of age\n- Needs to have Finnish social security number\n- Needs to have permanent street address in Finland\n\nIn case user is not a S-group co-op member there is a minimum of 20€ membership payment that needs to be made during the process.\n\nOnly vulnerabilities under domains https://digili.s-cloud.fi/ and https://api.digili.s-cloud.fi are eligible for bounty.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "extranet.s-pankki.fi",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-Bank portal where customers can take care of their S-Bank actions with other banks credentials. ",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "fi.spankki",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-mobiili banking application (Android).\n\nThe application can be found from Google Play https://play.google.com/store/apps/details?id=fi.spankki&hl=fi\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://crosskey.io/stores/s-pankki/apis",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-Bank PSD2 interface.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "mobile.s-pankki.fi",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-mobile banking application interface.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "online.s-pankki.fi",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-Bank netbank which provides netbank functionalities (accounts, payments, cards, loans, investments etc) to private customers. \n\nNotice that you should use your own netbank credentials or demo customer (ID: 12345678 PW: 123456) credentials. \n\nPlease ensure to place your @wearehackerone email into the User-Agent header when testing online.s-pankki.fi asset. Requests without this identification might be blocked.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "www.s-pankki.fi",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "S-bank public pages",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": []
}
}740514933· critical— none listed —