Bug Bounties

Priceline

Powered by: 

Allows bounty splitting: 

Average time to first program response: 3

Average time to bounty awarded null: 394

Average time to report resolved: 3296

Handle priceline

Managed program: true

Name: Priceline

Offers bounties: true

Offers swag: false

Response efficiency percentage: 94

Submission state: open

Url: https://hackerone.com/priceline

Website: http://www.priceline.com/

In scope:

  • Asset identifier: 336381998
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [iOS App](https://itunes.apple.com/us/app/priceline-hotel-travel-deals/id336381998?mt=8)
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: admin.rezserver.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Policy Guidance** We are not currently providing credentials for this asset. **Rules of Engagement** - In request headers use 'hackerone-{your username}' for user-agent - Keep low volume of requests - Automated testing is not permitted - Do not Fuzz Contact forms - Do not Fuzz "Request Account Activation" & "Request Product Activation" - Do not Fuzz request for "Change Request under Sites" - Do not modify other hacker_* user accounts under Hacker one test account **Non-Qualifying Vulnerabilities and Exclusions** - CSRF
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.rezserver.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Rezserver API** _Policy Guidance_ We are not currently providing credentials for this asset. _Rules_ - Don't use automated tools or scanners - Don't DDoS _Out of scope vulnerabilities_ - Missing best practices in HTTP header configuration. - Any activity that could lead to the disruption of our service (DoS) - Missing best practices in SSL/TLS configuration - Account/email enumeration issues - Disclosure of software version numbers (we maintain forks of several tools, and apply security patches accordingly) - Content Spoofing/Text Injection that cannot be leveraged for XSS or sensitive data disclosure _Endpoints out of scope_ - Hotel: BookRequest - Air: All endpoints - Car: All endpoints - Custom: All endpoints
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.priceline.android.negotiator
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: cruises.priceline.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: press.priceline.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: reservations.rezserver.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: secure.rezserver.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.bookingholdings.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: none
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: www.getaroom.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: www.priceline.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical