*.uberinternal.com· none*ubereats.com— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Uber.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 163,
"average_time_to_first_program_response": 60,
"average_time_to_report_resolved": null,
"handle": "uber",
"id": 0,
"managed_program": true,
"name": "Uber",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 68,
"submission_state": "open",
"url": "https://hackerone.com/uber",
"website": "https://www.uber.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.uberinternal.com",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "*ubereats.com",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Includes all subdomains (*.ubereats.com) except subdomains listed in out of scope.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "Recon Data",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Uber provides endpoints to determine whether an asset belongs to Uber:\n\nhttps://appsec-analysis.uber.com/public/bugbounty/ListDomains\nhttps://appsec-analysis.uber.com/public/bugbounty/ListIPs\n\nAll of the endpoints support offset and limit as optional parameters.\nExample: https://appsec-analysis.uber.com/public/bugbounty/ListDomains?offset=0&limit=100.\n\nThe public endpoints for asset information are for recon purposes. Information returned by those endpoints (or not) does not mean a bounty is guaranteed.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "uber.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "*.ubercarshare.com",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "*.uberscoot.us",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This asset is not eligible for Uber bounty programs.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "*.ubertransit.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This asset is not eligible for Uber bounty programs.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "*scaledsolutions.uber.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Fraud Reports",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Fraud reports are out of scope and ineligible for bounties. This includes reports detailing the ability to take free rides and evade payment.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "bizblog.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "central-beta.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "drive.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "eng.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "et.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "https://assets.uber.com",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "https://brand.uber.com",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "love.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "merchants.ubereats.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Reports of broken access control or privilege escalation that affect only organization‑scoped roles within the reporter’s own organization (e.g., a Staff role performing Manager‑only actions in the same organization) are out of scope for the Merchants application. This exclusion does not apply to cross‑tenant access, such findings remain in scope.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "newsroom.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "people.uber.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "scaledsolutions*.uber.com",
"asset_type": "WILDCARD",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "uber.com.cn",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Any asset under *.uber.com.cn is not eligible for Uber bounty programs. This and any other asset related to Uber in China belongs to Didi Chuxing.",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "uber.onelogin.com",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
}
]
}
}Recon Data· none*scaledsolutions.uber.comscaledsolutions*.uber.com*.ubercarshare.comFraud Reports