52235 policies in database
Link to program      
2024-01-17
2024-01-30
DataDome Bot Bounty logo
Thank
Gift
HOF
Reward

Reward

DataDome Bot Bounty

The goal of this program is to report ways around DataDome protection by implementing a scraping bot.

DataDome publishes these websites dedicated to researchers:

The technical challenge consists of scraping as much content as possible without being blocked by DataDome protection:

  • Minimum scenario: scraping content should be: 20000 web pages in less than an hour.
  • Medium scenario: 20000 web pages scraped in 30 minutes
  • High scenario: 20000 web pages scraped in 10 minutes
  • Critical scenario: 20000 web pages scraped in less than 1 minute

The report should contain:

  • A basic explanation of the attack vector used.
  • The code to reproduce the scraping scenario
  • The IP(s) used during the attack
  • The scraped content (hashes from the scraped pages) and HTTP requests return code (must be 200)
  • The scraping speed (in hits per sec.)

The report will be classified as a duplicate if a previous report generated the same code fix.

In Scope

Scope Type Scope Name
api

api-js.datadome.co

web_application

https://bounty-nodejs.datashield.co

web_application

https://bounty-fastly.datashield.co

web_application

https://bounty-nginx.datashield.co

web_application

*.captcha-delivery.com

web_application

js.datadome.co

Out of Scope

Scope Type Scope Name
undefined

Distributed attacks (scraping must be done using only 1 IP at a time).


Firebounty have crawled on 2024-01-17 the program DataDome Bot Bounty on the platform Yeswehack.

FireBounty © 2015-2024

Legal notices | Privacy policy