*ensemble*.yahoo.com· Tier 2*omega*.yahoo.com· Tier 2— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Yahoo Bug Bounty.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "d89a3560-be5c-406c-8a73-e4c72b0ca4c4",
"name": "Yahoo Bug Bounty",
"company_handle": "yahoo",
"handle": "yahoobugbounty",
"url": "https://www.intigriti.com/programs/yahoo/yahoobugbounty/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 100,
"currency": "USD"
},
"max_bounty": {
"value": 15000,
"currency": "USD"
},
"targets": {
"in_scope": [
{
"type": "wildcard",
"endpoint": "*ensemble*.yahoo.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "wildcard",
"endpoint": "*omega*.yahoo.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "7 News",
"description": "* [7News iOS](https://itunes.apple.com/au/app/7news/id439828000?mt=8)\n* [7News Android](https://play.google.com/store/apps/details?id=com.seven.news&hl=en_US)",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "apis.mail.yahoo.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "data.mail.yahoo.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Gemini",
"description": "* *.gemini.yahoo.com\n* *.admanager.yahoo.com",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Low Cost Access",
"description": "## In Scope ##\n* *.isp.netscape.com\n* *.compuserve.com\n* www.wmconnect.com\n\n## Other places to look ##\n* www.getnetscape.com\n* netscape.compuserve.com\n\n## Out of Scope ##\n* Subdomains of wmconnect.com outside of www\n\n## Notes ##\n* These services are designed for delivery through slow internet connections.\n* Registration for these services has been disabled.",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Identity Services",
"description": "## In Scope ##\n* https://login.yahoo.com\n* https://api.login.yahoo.com\n* http://credstore.yahoo.com/\n\nSome documentation that may help:\nhttps://developer.yahoo.com/oauth2/guide/\nSpecific paths to target….\nFor `login.*.com`\n* /account/logout\n* /auth/2.0/credentials\n* /auth/1.0/\n* /saml2/\n* /account\n* /oauth2\n* /ylc\n* /account/challenges\n* /account/access\n* /oauth2/device_auth\n* /ctv\n* /activate\n* /forgot\n\nFor `api.login.*.com`\n* /api\n* /oauth2/get_token\n* /oauth2/web_session\n* /oauth2/device_sessions\n* /oauth2/device_authorization\n* /oauth2/device_auth\n* /oauth2/revoke\n* /oauth2/introspect\n\n## Out of Scope ##\n* Any rate limits for authentication attempts. \n* Any differentiated treatment based on account, browser, IP address etc.\n\n## Limits ##\n* Limit traffic against our services to < 10/second when probing or testing.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "onepush.query.yahoo.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Other (Misc)",
"description": "Only use this asset when nothing else can be reasonably selected. \n\nBugs with Yahoo products that are not listed in scope of our [Public Program](https://app.intigriti.com/company/programs/yahoo/yahoobugbounty/detail) can still be submitted to this asset and _*might*_ be eligible for award, at the sole discretion of the Yahoo Bug Bounty team .\n\nUse this asset for:\n* `*.oath.cloud`\n* `*.yahoo.cloud`\n\n## Bastion Subdomains:\n* `bastion.*.oath.cloud`\n* `bastion.*.yahoo.cloud`\n\nNote: Reports of Bastion host subdomain takeovers submitted that only show takeover of the destination IP are most likely to be closed as `Informative` and not eligible for bounty. Most valid bugs will require a proof-of-concept or proof-of-exploit that escalates into one of the primary brand or product domains(e.g., yahoo.com, etc) to be potentially eligible for bounty.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "proddata.xobni.yahoo.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Social Media Accounts",
"description": "## Requirements\n* Account in question has posted content within 365 days of report submission\n* Account in question is related to a company, brand, or product\n* Exposed (valid/functional/active) credentials that allow login to an account\n\n## In Scope \n* Bounty: **Must meet all** `Requirements` above\n* Reputation: Meets at least one of the `Requirements` above\n* Note: “Account in question” means the account you are reporting as \"vulnerable.\"\n\n## Out of Scope\n* Account in question is related to an individual (employee, freelancer or otherwise)\n* Brute forcing account credentials",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TW eCommerce: Auctions",
"description": "## In Scope\n* [Yahoo TW Auctions Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.ecauction)\n* [Yahoo TW Auctions iOS](https://itunes.apple.com/tw/app/yahoo%E6%8B%8D%E8%B3%A3-%E5%88%8A%E7%99%BB%E5%85%8D%E8%B2%BB/id1033771352?mt=8)\n* Yahoo TW Auctions: \n * *.bid.yahoo.com\n * https://tw.bid.yahoo.com\n* Yahoo TW Auctions APIs:\n * https://tw.bid.yahoo.com/api/\n * https://tw.api.bid.yahoo.com:4443\n* Search API: tw.search.ec.yahoo.com\n\n## Notes\n* Access to the Taiwan sites from some countries in Europe may be blocked. \n* `Buyer` accounts can be set up for any Yahoo user.\n* `Seller` accounts require a TW phone number and 2FA.\n* **Do not** use fake data (like nid) when operating the cash functions, it may cause real money to be stuck; **we will hold you accountable for broken workflows.**\n* You are required to clean up all the testing data related to posting new products. \n* You **must** include the following “test” label in **ALL** posts (in the most visible location) to prevent regular users from interacting with hacker-created content: `[PARANOIDS-勿下標][TEST]`\n-- *Any reports identified that are missing this label, will not receive a bounty.*\n\n## Out of Scope\n* *.yahoo.com.tw\n* ismarus-ap-94600.tw.juiker.net\n* *.tw.juiker.net\n* auth.tw.juiker.net/oauth2/getUserTokenByTurnkey\n* *.straas.net\n* iOS: JuikerIMSDK.framework, StraaS-iOS-SDK\n* Android: io.straas.android.sdk\n* ecfme.famiport.com.tw (Third Party)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TW eCommerce: Shopping",
"description": "## In Scope\n* [Yahoo TW Shopping Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.ecshopping)\n* [Yahoo TW Shopping iOS](https://itunes.apple.com/tw/app/yahoo%E5%A5%87%E6%91%A9%E8%B3%BC%E7%89%A9%E4%B8%AD%E5%BF%83/id1061577845?mt=8)\n* Yahoo TW Shopping\n * twpay.buy.yahoo.com \n * Web: https://tw.buy.yahoo.com/\n * Mobile Web: https://m.tw.buy.yahoo.com/\n * API: https://tw.mapi.shp.yahoo.com and https://tw.ews.mall.yahooapis.com/\n* Search API: tw.search.ec.yahoo.com \n* Rushbuy API: rushbuy.buy.yahoo.com\n\n## Out of Scope\n* *.yahoo.com.tw\n* iOS: TPDirect.framework\n* Android: tech.cherri.tpdirect.api",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TW eCommerce: Used Car",
"description": "## In Scope\n* tw.usedcar.yahoo.com\n\n## Notes\nRefer to the ## Notes ## section in the `TW eCommerce: Auctions` listing.\n\n## Out of Scope\n* *.yahoo.com.tw\n* autos.yahoo.com.tw\n* tw.serviceplus.yahoo.com",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TW Media: Front Page",
"description": "## In Scope\n* tw.mobi.yahoo.com\n* tw.yahoo.com\n* Content API: https://ncp-gw-abu.media.yahoo.com/\n\n## Out of Scope\n* *.yahoo.com.tw",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TW Media: News",
"description": "## In Scope\n* [Yahoo TW News Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.newstw)\n* [Yahoo TW News iOS](https://itunes.apple.com/tw/app/yahoo%E5%A5%87%E6%91%A9-%E7%9B%B4%E6%92%ADlive-%E5%8D%B3%E6%99%82%E6%96%B0%E8%81%9E/id864844562?mt=8)\n* Yahoo TW News \n * *.tw.news.yahoo.com\n * Backend API: https://news-app.abumedia.yql.yahoo.com:443/ \n * Web: https://tw.news.yahoo.com\n * Content API: https://ncp-gw-abu.media.yahoo.com/\n\n## Out of Scope\n* news.campaign.yahoo.com.tw\n* *.yahoo.com.tw",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TW Media: Stock",
"description": "## In Scope\n* [Yahoo TW Stock Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.TWStock)\n* [Yahoo TW Stock iOS](https://itunes.apple.com/tw/app/yahoo%E5%A5%87%E6%91%A9%E8%82%A1%E5%B8%82/id790214428?mt=8)\n* Yahoo TW Stock\n * tw.stock.yahoo.com\n * API: https://stock-app.abumedia.yql.yahoo.com\n * API: https://tw-finance-yql.media.yahoo.com\n\n## Notes\n* `stock.yahoo.com` and `finance.yahoo.com` are identical; Reports will NOT be credited same-bug-different-host bonuses when issues are found on both domains.\n* TW Stock Apps have a strong dependency with third party SDK(s) for receiving the real-time quote data in the market. Every page containing values (volume, prices, up/down flag, …) of index, tickers, etfs, …, ticker information, line chart, notifications setting are all from the SDK. And the connection with the SDK service is established when the app launches and lasts the app's whole lifetime. **These SDK service(s) are out of scope.**\n\n## Out of Scope\n* *.yahoo.com.tw\n* tw.finance.yahoo.com\n* Quote SDK (from Systex inc.)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Calendar",
"description": "## In Scope\n* *.calendar.yahoo.com\n* *.caldav.calendar.yahoo.com\n\nSpecific paths to look at:\n* https://calendar.yahoo.com/ws/v3/users/\n* https://caldav.calendar.yahoo.com/principals/users/\n* https://caldav.calendar.yahoo.com/dav/*/calendar/\n\n## Limits\nLimit traffic against our services to < 10/second when probing or testing.",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Finance",
"description": "* [iOS](https://itunes.apple.com/us/app/yahoo-finance/id328412701?mt=8)\n* [Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.finance&hl=en_US)\n* *.finance.yahoo.com\n* OBI Premium Checkout: https://checkout.finance.yahoo.com/checkout/v1\n* API WebSockets Streaming Market Data: http://streamer.finance.yahoo.com\n* finance.mobile.yahoo.com\n* finance.query.yahoo.com",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo HK News",
"description": "* [Yahoo HK News Android](https://play.google.com/store/apps/details?id=com.yahoo.infohub)\n* [Yahoo HK News iOS](https://itunes.apple.com/hk/app/yahoo%E6%96%B0%E8%81%9E-%E9%A6%99%E6%B8%AF%E5%8D%B3%E6%99%82%E7%84%A6%E9%BB%9E/id425655609?mt=8)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Mail",
"description": "## In Scope\n* [Yahoo Mail (web)](https://mail.yahoo.com/)\n* [Yahoo Mail Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.mail)\n* [Yahoo Mail AndroidGo](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.mail.lite)\n* [Yahoo Mail iOS](https://itunes.apple.com/us/app/yahoo-mail-keeps-you-organized/id577586159?mt=8)\n* [Yahoo Mail FireOS](https://www.amazon.com/Yahoo-Mail-Keeps-you-organized/dp/B00632HWOG/)\n\n## Out of Scope:\n* mail.yahoo.com/cal/ (this is the same as `calendar.yahoo.com` and should be reported as Yahoo Calendar)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo News",
"description": "* [Newsroom Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.yahoo)\n* [Newsroom iOS](https://itunes.apple.com/us/app/newsroom-news-that-gets-you-talking/id304158842?mt=8)\n* *.news.yahoo.com\n* yahoo.com/news",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Open Source Projects",
"description": "## In Scope\n\n[Open Source Project Index \\- Yahoo Developer Network](https://developer.yahoo.com/opensource/projectindex/)\n\n## Bounty eligibility\n\n* Full bounty requires proof of impact to Yahoo production systems. \n* 50% bounty will be considered in cases where the last release date is within 1 year of the submission date, but no proof of impact to Yahoo systems. \n* No bounty if either conditions are not met.",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Search",
"description": "* [Yahoo Search Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.search)\n* [Yahoo Search iOS](https://itunes.apple.com/us/app/yahoo-search/id361071600?mt=8)\n* [Yahoo Search (web)](https://search.yahoo.com/)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Best Ball",
"description": "## In Scope ##\n* https://bestball.fantasysports.yahoo.com/",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Daily Fantasy",
"description": "## In Scope ##\n* https://sports.yahoo.com/dailyfantasy/\n* https://sports.yahoo.com/dailyfantasy/contest/create",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Editorial",
"description": "## In Scope ##\n* https://sports.yahoo.com/\n* https://api-secure.sports.yahoo.com\n\n ## Out of scope ##\n* shop.yahoosports.com (Third party)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Fantasy Games",
"description": "## In Scope ##\n* https://sports.yahoo.com/fantasy/\n* [Fantasy Basketball](https://basketball.fantasysports.yahoo.com/)\n* [Fantasy Hockey](https://hockey.fantasysports.yahoo.com/)\n* [Fantasy User Profiles](https://profiles.sports.yahoo.com/)\n* [Fantasy Football](https://football.fantasysports.yahoo.com/) (out of season)\n* [Public cookie-based API endpoints](https://pub-api-ro.fantasysports.yahoo.com/) (used by some FE stacks)\n* [Public OAuth2 endpoints](https://fantasysports.yahooapis.com/)\n* tournament.fantasysports.yahoo.com\n\n ## Out of Scope ##\n* *.sendbird.com (Third Party, SendBird)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Fantasy Slate/PicknWin",
"description": "## In Scope ## \n* https://sports.yahoo.com/fantasyslate",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Fantasy Sports",
"description": "## In Scope ## \n* [Yahoo Fantasy Sports Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.fantasyfootball)\n* [Yahoo Fantasy Sports iOS](https://itunes.apple.com/us/app/yahoo-fantasy-sports/id328415391?mt=8)\n* [Yahoo Fantasy Sports (web)](https://sports.yahoo.com/fantasy/)\n* https://sports.yahoo.com/odds/\n\n ## Notes ## \nThe betting feature in Fantasy is provided by a third party, BetMGM. https://sports.yahoo.com/odds/, is the page from where it redirects the user to the BetMGM. This is geographically restricted.",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Fantasy Wallet",
"description": "## In Scope ## \n* https://sports.yahoo.com/dailyfantasy/account/addfunds",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Sports: Mobile",
"description": "## In Scope ## \n* [Yahoo Sports Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.sportacular)\n* [Yahoo Sports iOS](https://itunes.apple.com/us/app/yahoo-sports-teams-scores-news-highlights/id286058814?mt=8)\n* *.protrade.com",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Video",
"description": "* [Yahoo Video FireTV](https://www.amazon.com/Yahoo-for-Fire-TV/dp/B014X5UGPQ/)\n* [Yahoo Video tvOS](https://itunes.apple.com/us/app/yahoo-watch-free-live-concerts-sports-video-clips-and-more/id1046996690?mt=8)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo Weather",
"description": "* [Yahoo Weather Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.weather)\n* [Yahoo Weather iOS](https://itunes.apple.com/us/app/yahoo-weather/id628677149?mt=8)\n* [Yahoo Weather (web)](https://www.yahoo.com/news/weather/)",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Yahoo! (Misc)",
"description": "## Notes\nOnly use this asset when nothing else can be reasonably selected.\n\nBugs with Yahoo! that are not listed in scope of our other Yahoo-related assets can still be submitted to this asset and **_*might*_** be eligible for award, at the sole discretion of the Yahoo Bug Bounty team.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "yimg.com",
"description": "yimg is a resource storage and content distribution network (CDN).\n** Note: Reports submitted that exploit bugs only in the context of the `yimg.com` domain are most likely to be closed as `Informative`. Most bugs in `*.yimg.com` will require a proof-of-concept or proof-of-exploit that escalates into one of the primary brand or product domains (e.g. yahoo.com) to be eligible for bounty. CVSS Environmental scores have been set to account for this limitation.**\n\nWhat does that mean for my report?\n1. If you show escalation into a trusted domain's context (such as yahoo.com) it will be accepted at 100% bounty rate. A bonus may be applied for different instances within the trusted domain list only; not for other instances of vulnerabilities content on yimg.com.\n2. If you show execution in the context of *.yimg.com only, the vulnerability MAY be accepted by the business owner in some instances. In that case, a minimum bounty would be offered only if the content is removed. There are no \"same bug different host\" or other vulnerability grouping bonus offers for this asset.",
"impact": "Tier 2"
}
],
"out_of_scope": [
{
"type": "other",
"endpoint": "Flurry",
"description": "* [Flurry Android](https://play.google.com/store/apps/details?id=com.yahoo.flurry)\n* [Flurry iOS](https://itunes.apple.com/us/app/flurry-analytics/id1079687315?mt=8)\n* *.flurry.com\n* monetization.flurry.com",
"impact": "Out of scope"
},
{
"type": "other",
"endpoint": "TW eCommerce: Store",
"description": "## In Scope\n* [Yahoo TW Store Android](https://play.google.com/store/apps/details?id=com.yahoo.mobile.client.android.ecstore)\n* [Yahoo TW Store iOS](https://itunes.apple.com/tw/app/yahoo%E5%A5%87%E6%91%A9%E8%B6%85%E7%B4%9A%E5%95%86%E5%9F%8E/id778296354?mt=8)\n* Yahoo TW Store\n * *.tw.mall.yahoo.com\n * m.mall.yahoo.com\n * Web: https://tw.mall.yahoo.com/\n * Mobile Web: https://m.tw.mall.yahoo.com/\n * API: https://tw.ews.mall.yahooapis.com/\n* Search API: tw.search.ec.yahoo.com\n\n## Out of Scope\n* *.yahoo.com.tw",
"impact": "Out of scope"
}
]
}
}7 News· Tier 2Gemini· Tier 2Low Cost Access· Tier 2Identity Services· Tier 2Other (Misc)· Tier 2Social Media Accounts· Tier 2TW eCommerce: Auctions· Tier 2TW eCommerce: Shopping· Tier 2TW eCommerce: Used Car· Tier 2TW Media: Front Page· Tier 2TW Media: News· Tier 2TW Media: Stock· Tier 2Yahoo Calendar· Tier 2Yahoo Finance· Tier 2Yahoo HK News· Tier 2Yahoo Mail· Tier 2FlurryotherTW eCommerce: StoreotherYahoo News· Tier 2Yahoo Open Source Projects· Tier 2Yahoo Search· Tier 2Yahoo Sports: Best Ball· Tier 2Yahoo Sports: Daily Fantasy· Tier 2Yahoo Sports: Editorial· Tier 2Yahoo Sports: Fantasy Games· Tier 2Yahoo Sports: Fantasy Slate/PicknWin· Tier 2Yahoo Sports: Fantasy Sports· Tier 2Yahoo Sports: Fantasy Wallet· Tier 2Yahoo Sports: Mobile· Tier 2Yahoo Video· Tier 2Yahoo Weather· Tier 2Yahoo! (Misc)· Tier 2