Bug Bounties

Slack

Powered by: 

Allows bounty splitting: 

Average time to first program response: 

Average time to bounty awarded null: 

Average time to report resolved: 

Handle slack

Managed program: false

Name: Slack

Offers bounties: true

Offers swag: false

Response efficiency percentage: 89

Submission state: open

Url: https://hackerone.com/slack

Website: https://slack.com

In scope:

  • Asset identifier: *.quip.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 647922896
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: itunes.apple.com/us/app/quip-docs-chat-sheets/id647922896
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.slack.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The Slack API
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: app.slack.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.Slack
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.quip.quip
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: https://play.google.com/store/apps/details?id=com.quip.quip&hl=en_US
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.slack.slackmdm
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Reports are accepted for vulnerabilities specific to the [Slack EMM/MDM version of the app](https://apps.apple.com/us/app/slack-for-emm/id1254292716). EMM client vulnerabilities in the absence of a valid MDM configuration via a supported MDM provider, (such as MobileIron), on an EMM-enabled Slack team are excluded.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.tinyspeck.chatlyio
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The main Slack app is included: [Slack iOS App](https://apps.apple.com/us/app/slack/id618783545) Other versions of the app, such as the EMM and Intune versions, are not included.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: edgeapi.slack.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://github.com/slackhq/nebula
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Only Critical reports for this component will be accepted and paid.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://salesforce.quip.com/blog/desktop
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: slack-imgs.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Only Critical severity reports for this domain will be accepted and paid.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: slack-redir.net
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Only Critical severity reports for this domain will be accepted and paid. Reports for open redirects are unlikely to be rewarded.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: slack.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The slack.com site and application.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: slackatwork.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Only Critical severity reports for this domain will be accepted and paid.
  • Integrity requirements: low
  • Max severity: critical



  • Asset identifier: slackb.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: spaces.pm
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Only Critical severity reports for this domain will be accepted and paid.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: status.slack.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The Slack status site
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.quip.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical