Bug Bounties

UPchieve

Powered by: 

Allows bounty splitting: 

Average time to first program response: 1

Average time to bounty awarded null: 

Average time to report resolved: 

Handle upchieve

Managed program: false

Name: UPchieve

Offers bounties: false

Offers swag: false

Response efficiency percentage: 67

Submission state: open

Url: https://hackerone.com/upchieve

Website: https://upchieve.org

In scope:

  • Asset identifier: 1506076042
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: We are open source. The code for our mobile app is at https://gitlab.com/upchieve/mta
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Our infrastructure hosted in Azure Cloud
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: We are open-source, and keep all our infrastructure setup in [Pulumi](https://www.pulumi.com) code. The repository with our infrastructure code is at https://www.gitlab.com/upchieve/grand-central-station
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: argocd.upchieve.org
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This is our continuous delivery platform, [ArgoCD](https://argoproj.github.io/argo-cd/). It is deployed via Kubernetes yamls in https://gitlab.com/upchieve/grand-central-station. It is the only publicly exposed part of our infrastructure other than the main app.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: hackers.upchieve.org
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This is our hacker specific site that matches our production environment. We are open source; source code for this application can be found at https://gitlab.com/upchieve/subway The Helm chart deployment code for the app is at https://gitlab.com/upchieve/port-authority Logins for this environment for testing purposes: Students: teststudent1@upchieve.org teststudent2@upchieve.org Volunteers: testvolunteer1@upchieve.org testvolunteer2@upchieve.org Admin: testadmin1@upchieve.org Password for both students is Demostudentpassword! Password for all volunteers is Demovolunteerpassword!
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://gitlab.com/upchieve/subway
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical