Scope

Informational

Scope

Definition

The Scope in bug bounty defines which assets, domains, features and vulnerability types are valid to report. Every bug bounty program has a specific scope that includes the 'in scope' assets (where you can hunt) and the 'out of scope' ones (where you can't). Understanding and respecting the scope is essential to avoid invalid reports and possible legal consequences.

Impact

Defines which assets are valid for researchDetermines which vulnerability types are acceptedLegal protection for the researcher within the defined scopePrioritization of effort on higher-reward assetsOut-of-scope reports are rejected and hurt your reputation

Examples

Example of a typical scope in a bug bounty program

A typical program defines: In Scope: *.example.com (wildcard), app.example.com, api.example.com. Out of Scope: blog.example.com (WordPress managed by third parties), staging.example.com. Accepted vulnerabilities: XSS, SSRF, SQLi, IDOR, RCE. Excluded: Self-XSS, logout CSRF, rate limiting, missing captcha, open ports without demonstrated impact.

Practice Scope with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime