Powered by: Allows bounty splitting:
Average time to first program response: 15
Average time to bounty awarded null: 204
Average time to report resolved: 2810
Handle snapchat
Managed program: false
Name: Snapchat
Offers bounties: true
Offers swag: false
Response efficiency percentage: 99
Submission state: open
Url: https://hackerone.com/snapchat
Website: https://www.snapchat.com/
In scope: Asset identifier: *.sc-core.netAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's internal servicesIntegrity requirements: highMax severity: criticalAsset identifier: Lens StudioAsset type: DOWNLOADABLE_EXECUTABLESAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Downloadable at https://lensstudio.snapchat.com/download/Integrity requirements: lowMax severity: mediumAsset identifier: SpectaclesAsset type: HARDWAREAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: [Core hardware]
Specifically interested in Remote Code Execution on Spectacles (over the air). Integrity requirements: lowMax severity: highAsset identifier: accounts.snapchat.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
Snapchat's account management website. Integrity requirements: highMax severity: criticalAsset identifier: ads.snapchat.comAsset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: mediumMax severity: highAsset identifier: app.snapchat.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
Main server-side application hosted on Google App Engine under the hostname feelinsonice-hrd.appspot.com and app.snapchat.com.Integrity requirements: highMax severity: criticalAsset identifier: business.snapchat.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's Business Manager. Integrity requirements: highMax severity: criticalAsset identifier: businesshelp.snapchat.comAsset type: URLAvailability requirement: mediumConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's Salesforce instanceIntegrity requirements: lowMax severity: highAsset identifier: com.bitstrips.imojiAsset type: APPLE_STORE_APP_IDAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: [Non-core asset]
[iOS App Store](https://itunes.apple.com/us/app/bitmoji-keyboard-your-avatar/id868077558)Integrity requirements: lowMax severity: mediumAsset identifier: com.bitstrips.imojiAsset type: GOOGLE_PLAY_APP_IDAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: [Non-core asset]
[Google Play Store](https://play.google.com/store/apps/details?id=com.bitstrips.imoji)Integrity requirements: lowMax severity: mediumAsset identifier: com.snapchat.androidAsset type: GOOGLE_PLAY_APP_IDAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
[Google Play Store](https://play.google.com/store/apps/details?id=com.snapchat.android)Integrity requirements: lowMax severity: highAsset identifier: com.toyopagroup.picabooAsset type: APPLE_STORE_APP_IDAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
[iOS App Store](https://itunes.apple.com/us/app/snapchat/id447188370?mt=8)Integrity requirements: lowMax severity: highAsset identifier: create.snapchat.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's Geofilter creation tool. Integrity requirements: lowMax severity: highAsset identifier: geofilters.snapchat.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
Snapchat's on-demand Geofilters purchase website. Integrity requirements: lowMax severity: highAsset identifier: https://lensstudio.snapchat.com/api/Asset type: SOURCE_CODEAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's Javascript Lenses APIIntegrity requirements: highMax severity: criticalAsset identifier: kit.snapchat.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
SNAPKIT web application and SDKsIntegrity requirements: lowMax severity: highAsset identifier: map.snapchat.comAsset type: URLAvailability requirement: noneConfidentiality requirement: noneEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: lowAsset identifier: my.snapchat.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's Spotlight on the web. Integrity requirements: lowMax severity: highAsset identifier: scan.snapchat.comAsset type: URLAvailability requirement: noneConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
Snapcode creation websiteIntegrity requirements: noneMax severity: lowAsset identifier: snappublisher.snapchat.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
Snapchat's publisher tool. Integrity requirements: lowMax severity: highAsset identifier: spectacles.comAsset type: URLAvailability requirement: noneConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: [Core asset]
Snapchat's spectacles purchase website. Integrity requirements: noneMax severity: lowAsset identifier: store.snapchat.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Snapchat's Bitmoji Merch StoreIntegrity requirements: Max severity: criticalAsset identifier: story.snapchat.comAsset type: URLAvailability requirement: noneConfidentiality requirement: noneEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: lowAsset identifier: web.snapchat.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: highMax severity: criticalAsset identifier: www.bitmoji.comAsset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: [Non-core asset]Integrity requirements: lowMax severity: mediumAsset identifier: www.bitstrips.comAsset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: [Non-core asset]Integrity requirements: lowMax severity: medium