PentestingHere
Log in Join

Netflix

Netflix on HackerOne · HackerOne Active

Official page

Scope

At a glance

  • Bounties: Yes
  • Swag: No
  • Managed by the platform: Yes
  • Average first response: 0.1 days
  • Average time to resolution: 22.3 days

In scope

  • *.nflxext.com
  • *.nflximg.net
  • *.nflxso.net
  • *.nflxvideo.net
  • *.prod.cloud.netflix.com
  • *.prod.dradis.netflix.com
  • *.prod.ftl.netflix.com
  • Affiliates or entities such as recently acquired companies
  • Content Authorization Targets
  • Content authorization vulnerabilities affecting only the in-browser player
  • Corporate Assets
  • Low impact, individually exposed Google Docs with no common root cause (see “Publicly accessible Google Document or Driv...
  • Microsites
  • Netflix Gaming Target
  • Netflix Mobile Application for Android
  • Netflix Mobile Application for iOS
  • Open Source - Atlas
  • Open Source - Spectator
  • Open Source - Zuul
  • Secondary Assets
  • api*.netflix.com
  • beacon.netflix.com
  • customerevents.netflix.com
  • help.netflix.com
  • ichnaea.netflix.com
  • meechum.netflix.com
  • nmtracking.netflix.com
  • presentationtracking.netflix.com
  • secure.netflix.com
  • www.netflix.com

Out of scope

  • Assets associated with ReadyPlayerMe
  • Open Source - Consoleme
  • Open Source - Dispatch
  • Open Source - Weep
  • Set-top-boxes, smart TVs, streaming sticks Out of Scope
  • Third party websites or systems hosted by non-Netflix entities Out of Scope
  • ir.netflix.com
  • ir.netflix.net
  • netflixinvestor.com

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback