Bug Bounties

IRCCloud

Powered by: 

Allows bounty splitting: 

Average time to first program response: 

Average time to bounty awarded null: 

Average time to report resolved: 

Handle irccloud

Managed program: false

Name: IRCCloud

Offers bounties: true

Offers swag: true

Response efficiency percentage: 90

Submission state: open

Url: https://hackerone.com/irccloud

Website: https://www.irccloud.com

In scope:

  • Asset identifier: *.irccloud-cdn.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Please note that this domain hosts user-uploaded files which are intentionally public for sharing on IRC. These do not constitute an information disclosure vulnerability and reports will be closed as "Not Applicable".
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.irccloud.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: In particular IRC connection hosts listed here: https://www.irccloud.com/networks
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.irccloud.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: blog.irccloud.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: com.irccloud.IRCCloud
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The iOS app is open source, decompilation issues are not eligible https://github.com/irccloud/ios Vulnerabilities requiring local or root access to a device are also not eligible.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.irccloud.android
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The Android app is open source, decompilation issues are not eligible https://github.com/irccloud/android Vulnerabilities requiring local or root access to a device are also not eligible.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: https://github.com/irccloud/android
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: https://github.com/irccloud/ios
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: https://github.com/irccloud/irccloud-desktop
  • Asset type: SOURCE_CODE
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: Our desktop app is pre-release and not officially supported or promoted, we are not ready to issue bounties for it.
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: irc.irccloud.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Support IRC network.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: irccloud.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: team-irc.irccloud.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Private team IRC servers
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: www.irccloud.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical