*.sip.*.twilio.com· criticalstatic*.twilio.com· critical— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Twilio.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 27,
"average_time_to_first_program_response": 1,
"average_time_to_report_resolved": 2009,
"handle": "twilio",
"id": 0,
"managed_program": true,
"name": "Twilio",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 84,
"submission_state": "open",
"url": "https://hackerone.com/twilio",
"website": "https://www.twilio.com/",
"targets": {
"in_scope": [
{
"asset_identifier": "*.sip.*.twilio.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Any host/web property verified to be owned by Twilio et al.",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Any host/web property verified to be owned by Twilio (domains/IP space/etc.) but not listed in the previous target groups and not listed as Out of Scope.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Twilio APIs",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "api.segment.io",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "### Access & Testing (Segment)\nLimit your use of scanner tests based on our technology stack. Our application is primarily powered by Node.js, React, and GraphQL.\nTo test Segment you'll need to create a variety of data sources/destinations. We would recommend using those that have a bug bounty program such as Intercom, Twilio, Facebook, or Google. Services like Heroku can be valuable for creating resources such as Postgres instances to test our warehouse's products.\n\n### Libraries (Segment)\nSegment provides libraries written in various languages to our customers https://segment.com/docs/connections/sources/. We invite you to review the source code of our Website, Mobile, and Server Libraries, all of which are hosted on Github. Qualifying submissions must have a demonstrable impact and realistic attack vector. Submissions that include a proposed fix will be easier for us to evaluate and reward.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "api.sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "api.twilio.com",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "app.segment.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "###Access & Testing (Segment)\nLimit your use of scanner tests based on our technology stack. Our application is primarily powered by Node.js, React, and GraphQL.\nTo test Segment you'll need to create a variety of data sources/destinations. We would recommend using those that have a bug bounty program such as Intercom, Twilio, Facebook, or Google. Services like Heroku can be valuable for creating resources such as Postgres instances to test our warehouse's products.\n\n###Libraries (Segment)\nSegment provides libraries written in various languages to our customers https://segment.com/docs/connections/sources/. We invite you to review the source code of our Website, Mobile, and Server Libraries, all of which are hosted on Github. Qualifying submissions must have a demonstrable impact and realistic attack vector. Submissions that include a proposed fix will be easier for us to evaluate and reward.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "app.sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "http://help.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "http://tsock.us1.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "http://twilio.com/blog",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://segment.com/docs/connections/sources/",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "##Source code of Website, Mobile, or Server Libraries\n###Access & Testing (Segment)\nLimit your use of scanner tests based on our technology stack. Our application is primarily powered by Node.js, React, and GraphQL.\nTo test Segment you'll need to create a variety of data sources/destinations. We would recommend using those that have a bug bounty program such as Intercom, Twilio, Facebook, or Google. Services like Heroku can be valuable for creating resources such as Postgres instances to test our warehouse's products.\n\n###Libraries (Segment)\nSegment provides libraries written in various languages to our customers https://segment.com/docs/connections/sources/. We invite you to review the source code of our Website, Mobile, and Server Libraries, all of which are hosted on Github. Qualifying submissions must have a demonstrable impact and realistic attack vector. Submissions that include a proposed fix will be easier for us to evaluate and reward.\n\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.authy.com/download/",
"asset_type": "APPLE_STORE_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.authy.com/download/",
"asset_type": "GOOGLE_PLAY_APP_ID",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.twilio.com/docs/authy/api",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Authy API",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.twilio.com/docs/libraries",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nTwilio SDKs \n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.\n\n\n\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.twilio.com/docs/verify/api",
"asset_type": "API",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Verify",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.twilio.com/en-us/blog/get-started-webrtc",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nTwilio WebRTC Client\n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://www.twilio.com/login?g=%2fconsole%3f&t=2b1c98334b25c1a785ef15b6556396290e3c704a9b57fc40687cbccd79c46a8c",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio Primary Targets\n\nTwilio Console\n\nMany of our Twilio APIs are available in our Postman collection. Please confirm that your target is within scope before testing. Do not publicly store any sensitive information.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "mc.sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "signup.sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "smtp.sendgrid.net",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "static*.twilio.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Twilio CDNs",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "All Kurento domains",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "All Twilio acquisitions until explicitly noted under the in-scope targets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Electric Imp and its assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Third-party services",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Twilio Quest",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Twilio Wireless",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "TwimlBins",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Ytica and its assets",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "community.segment.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "http://apjevents.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "http://events.cdpweek.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "http://segment.com/contact",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "http://segment.com/jobs",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "http://twilio.com/en-us/company/jobs",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "http://twilio.com/labs",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "jobs.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "lab.authy.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "signal.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "status.segment.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "status.sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "status.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "store.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "support.sendgrid.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "support.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "surveys.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "talks.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "transform.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "twil.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "twiliotraining.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "webinars.segment.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "webinars.twilio.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "zipwhip.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}Any host/web property verified to be owned by Twilio et al.· criticalwww.authy.com/download/· criticalwww.twilio.com/docs/libraries· criticalwww.twilio.com/en-us/blog/get-started-webrtc· criticalsmtp.sendgrid.net· criticalAll Kurento domainsAll Twilio acquisitions until expl…ed under the in-scope targetsElectric Imp and its assetsThird-party servicesTwilio QuestTwilio WirelessTwimlBinsYtica and its assets