— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for DataDome Bot Bounty.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "datadome-bot-bounty",
"name": "DataDome Bot Bounty",
"public": true,
"disabled": false,
"managed": null,
"min_bounty": 200,
"max_bounty": 1000,
"targets": {
"in_scope": [
{
"target": "https://bounty-nodejs.datashield.co",
"type": "web-application"
},
{
"target": "https://bounty-fastly.datashield.co",
"type": "web-application"
},
{
"target": "https://bounty-nginx.datashield.co",
"type": "web-application"
},
{
"target": "*.captcha-delivery.com",
"type": "web-application"
},
{
"target": "js.datadome.co",
"type": "web-application"
},
{
"target": "api-js.datadome.co",
"type": "api"
}
],
"out_of_scope": [
{
"target": "Distributed attacks (scraping must be performed from a single IP at a time)",
"type": "other"
},
{
"target": "Denial of service attacks or any technique whose goal is to degrade infrastructure availability. This falls outside the scope of bot protection bypass and will not be rewarded.",
"type": "other"
},
{
"target": "Social engineering of DataDome employees or contractors",
"type": "other"
},
{
"target": "Client-side web vulnerabilities",
"type": "other"
}
]
}
}bounty-fastly.datashield.coDistributed attacks (scraping must…d from a single IP at a time)otherDenial of service attacks or any t…ass and will not be rewarded.otherSocial engineering of DataDome employees or contractorsotherClient-side web vulnerabilitiesother