Bug Bounties

Unikrn

Powered by: 

Allows bounty splitting: 

Average time to first program response: 

Average time to bounty awarded null: 

Average time to report resolved: 

Handle unikrn

Managed program: false

Name: Unikrn

Offers bounties: true

Offers swag: false

Response efficiency percentage: 33

Submission state: open

Url: https://hackerone.com/unikrn

Website: https://unikrn.com

In scope:

  • Asset identifier: affiliates.unikrn.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Third party affiliate platform
  • Integrity requirements: medium
  • Max severity: high



  • Asset identifier: api-w.unikrnb2b.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: This is part of our B2B offering [start test session][1] [1]: https://api-w.unikrnb2b.com/apiv1/unk/start/sport_id=85
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.unikrn.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: B2C Data Endpoints
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: auctionbot.unikrn.com
  • Asset type: URL
  • Availability requirement: medium
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Websocket
  • Integrity requirements: medium
  • Max severity: critical



  • Asset identifier: auth.unikrn.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Auth Services - OAuth2
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: connekt-api.unikrn.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: medium
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Connekt/Umode Apis
  • Integrity requirements: medium
  • Max severity: critical



  • Asset identifier: crm.unikrn.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: medium
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Admin only login CRM page based on [Mautic][1] [1]: https://github.com/mautic/mautic
  • Integrity requirements: medium
  • Max severity: critical



  • Asset identifier: jet-api.unikrn.com
  • Asset type: URL
  • Availability requirement: medium
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Account and Betting Api
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: news.unikrn.com
  • Asset type: URL
  • Availability requirement: medium
  • Confidentiality requirement: low
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Specific news portal site
  • Integrity requirements: medium
  • Max severity: critical



  • Asset identifier: unikrn.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Main B2C page, and API endpoint(s)
  • Integrity requirements: high
  • Max severity: critical