Bug Bounties

Internet Bug Bounty

Powered by: 

Allows bounty splitting: 

Average time to first program response: 143

Average time to bounty awarded null: 

Average time to report resolved: 

Handle ibb

Managed program: false

Name: Internet Bug Bounty

Offers bounties: true

Offers swag: false

Response efficiency percentage: 76

Submission state: open

Url: https://hackerone.com/ibb

Website: https://www.hackerone.com/internet-bug-bounty

In scope:

  • Asset identifier: https://git.libssh.org/
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://www.libssh.org/development/security-process/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/Electron
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Build cross platform desktop apps with JavaScript, HTML, and CSS. Disclosure instructions: https://github.com/electron/electron/security/policy
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/Nginx
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: http://nginx.org/en/security_advisories.html
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/apache/airflow
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://github.com/apache/airflow/security/policy
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/apache/httpd
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: http://httpd.apache.org/security_report.html
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/argoproj/argoproj
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://github.com/argoproj/argoproj/blob/master/SECURITY.md Project Modifier: bounty amounts for this project are adjusted based on the following criteria: -50% : Vulnerability is not exploitable in a default configuration of Argo.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/curl/curl
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://github.com/curl/curl/blob/master/docs/SECURITY-PROCESS.md
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/django
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The Web framework for perfectionists with deadlines. Disclosure instructions: https://www.djangoproject.com/security/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/nodejs/node
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://hackerone.com/nodejs **Project Modifier:** bounty amounts for this project are adjusted based on the following criteria: -50% : Vulnerability is not exploitable in a default configuration of Node.js. -25% : A proposed patch was not provided for the issue.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/openssl/openssl
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: OpenSSL. Disclosure instructions: https://www.openssl.org/news/vulnerabilities.html
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/rack/rack
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://github.com/rack/rack/security/policy
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/rails
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Ruby on Rails. Disclosure Instructions: https://rubyonrails.org/security/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/ruby
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The Ruby Programming Language. Disclosure Instructions: https://www.ruby-lang.org/en/security/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/rubygems/rubygems
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Library packaging and distribution for Ruby. Disclosure instructions: https://guides.rubygems.org/security/#reporting-security-vulnerabilities
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/rust-lang/rust
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Rust Programming Language. Disclosure Instructions: https://www.rust-lang.org/policies/security
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/spiffe/spiffe
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: If you've found a vulnerability or a potential vulnerability in SPIFFE please report it at security@spiffe.io.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/spiffe/spire
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://github.com/spiffe/spire/security/policy
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://wiki.xenproject.org/wiki/Xen_Project_Repositories
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: https://xenproject.org/developers/security-policy/ Eligible scope only includes issues for which an XSA is issued.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: rubygems.org
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Disclosure instructions: Submit any new or potential vulnerabilities for rubygems.org to https://hackerone.com/rubygems
  • Integrity requirements: 
  • Max severity: critical