— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Alasco GmbH - Bug Bounty Program.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "alasco-gmbh-bug-bounty-program",
"name": "Alasco GmbH - Bug Bounty Program",
"public": true,
"disabled": false,
"managed": null,
"min_bounty": 50,
"max_bounty": 1000,
"targets": {
"in_scope": [
{
"target": "app.alasco.de",
"type": "web-application"
},
{
"target": "api.alasco.de",
"type": "api"
},
{
"target": "*.alasco.de",
"type": "other"
},
{
"target": "*.alasco.rocks",
"type": "other"
}
],
"out_of_scope": [
{
"target": "All other domains or subdomains not listed in the above list of 'Scopes'.",
"type": "other"
},
{
"target": "explore.alasco.com",
"type": "other"
},
{
"target": "explore.alasco.de",
"type": "other"
},
{
"target": "www.alasco.de",
"type": "other"
},
{
"target": "www.alasco.com",
"type": "other"
},
{
"target": "alasco.de",
"type": "other"
},
{
"target": "alasco.com",
"type": "other"
},
{
"target": "lp.alasco.de",
"type": "other"
},
{
"target": "lp.alasco.com",
"type": "other"
},
{
"target": "support.alasco.de",
"type": "other"
},
{
"target": "support.alasco.com",
"type": "other"
},
{
"target": "Please note that all non-authenticated areas of our systems are in scope for this program. This means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a reward.",
"type": "other"
},
{
"target": "However, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this program.",
"type": "other"
},
{
"target": "Alasco will not provide access credentials to any system, not for testing and also not for issue validation.",
"type": "other"
},
{
"target": "Attention: Third-party managed infrastructure (e.g. HubSpot, Salesforce, or other SaaS platforms) where Alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomain.",
"type": "other"
}
]
}
}*.alasco.deAll other domains or subdomains no…n the above list of 'Scopes'.otherexplore.alasco.comotherexplore.alasco.deotherwww.alasco.deotherwww.alasco.comotheralasco.deotheralasco.comotherlp.alasco.deotherlp.alasco.comothersupport.alasco.deothersupport.alasco.comotherPlease note that all non-authentic…ess is eligible for a reward.otherHowever, any vulnerability discove…de the scope of this program.otherAlasco will not provide access cre…lso not for issue validation.Attention: Third-party managed inf… regardless of the subdomain.other