Program Scopes
In a Bug Bounty program, a Scope is an asset that organisations want to be tested.
Scopes may include:
Web applications
Mobile applications (iOS and/or Android)
APIs
Desktop software
IoT devices
Firmware
IP addresses
Cloud infrastructure or third-party services
Etc.
π‘ This list is essential to know what you are allowed to test in the framework of this program.
These are the only assets eligible for a reward if a (valid) vulnerability is found.
Rewards
Rewards depend on 2 criteria:
Final CVSS score after company's assessment
Applicable reward grid for the vulnerable scope
β οΈ Reward grids are defined as the potential maximum reward per severity level.
For example:
If you were to find a valid vulnerability on a critical scope (e.g., https://yeswehack.com) you might be rewarded up to 15000β¬.