Netflix
Netflix on HackerOne · HackerOne Active
Scope
At a glance
- Bounties: Yes
- Swag: No
- Managed by the platform: Yes
- Average first response: 0.1 days
- Average time to resolution: 22.3 days
In scope
*.nflxext.com*.nflximg.net*.nflxso.net*.nflxvideo.net*.prod.cloud.netflix.com*.prod.dradis.netflix.com*.prod.ftl.netflix.comAffiliates or entities such as recently acquired companiesContent Authorization TargetsContent authorization vulnerabilities affecting only the in-browser playerCorporate AssetsLow impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Driv...MicrositesNetflix Gaming TargetNetflix Mobile Application for AndroidNetflix Mobile Application for iOSOpen Source - AtlasOpen Source - SpectatorOpen Source - ZuulSecondary Assetsapi*.netflix.combeacon.netflix.comcustomerevents.netflix.comhelp.netflix.comichnaea.netflix.commeechum.netflix.comnmtracking.netflix.compresentationtracking.netflix.comsecure.netflix.comwww.netflix.com
Out of scope
Assets associated with ReadyPlayerMeOpen Source - ConsolemeOpen Source - DispatchOpen Source - WeepSet-top-boxes, smart TVs, streaming sticks Out of ScopeThird party websites or systems hosted by non-Netflix entities Out of Scopeir.netflix.comir.netflix.netnetflixinvestor.com
Imported from the public directory. Always confirm scope on the official program page before testing.