Keeping traveller's information safe and secure is a top priority for Skyscanner. We welcome the contribution of security researchers and look forward to rewarding them for their invaluable contribution to the security of all Skyscanner travellers.
We invite researchers to test the Skyscanner website and mobile apps in line with the principles set out in this brief.
We request thorough proof-of-concept/replication of the bug, including videos, images, and a description of the business impact. These will all factor into our bounty decision-making process.
To promote the discovery and reporting of vulnerabilities we ask that you:
We expect researchers to follow the program rules:
Researchers must:
In addition, we count the following activities as strictly prohibited, and thus not rewardable. These are in addition to the Bugcrowd Vulnerability Rating Taxonomy:
We will offer monetary rewards for the first submitted report of a vulnerability.
Public disclosure of the vulnerability prior to resolution may cancel a pending reward. We reserve the right to disqualify individuals from the program for disrespectful or disruptive behaviour.
We will not negotiate in response to duress or threats (e.g. we will not negotiate the payout amount under threat of withholding the vulnerability, or of releasing the vulnerability or any exposed data to the public).
We reserve the right to deduct a 10% penalty on valid and accepted submissions that do not follow the guidelines mentioned above. Following the guidelines will help us triage the vulnerability more effectively from our side, which should result in faster processing of the submission
We are under no obligation to pay out for any bugs that are not submitted in accordance with this policy or any of the Bugcrowd policies.
We reserve the right to withdraw this scheme at any time and shall have no obligation to pay out for any bugs submitted after closure of the scheme.
For the initial prioritization/rating of findings, this program uses the Bugcrowd Vulnerability Rating Taxonomy. However, please note that in some cases, the priority rating will be altered due to reflect the likelihood or impact of an exploit. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
We will award greater bounties for all valid submissions contained in our Focus Areas (see Target Information).
Priority | Reward range |
---|---|
P1 | $2,000 – $4,000* |
P2 | $900 – $1,500* |
P3 | $300 – $400 |
P4 | $100 – $150 |
*The highest rewards will be reserved for submissions deemed to have high business criticality.
When conducting vulnerability research according to this policy, we consider this research to be:
You are expected, as always, to comply with all applicable laws.
If at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | Skyscanner Android App |
api | gateway.skyscanner.net/* |
ios_application | Skyscanner iOS App |
web_application | skyscanner.net/hotels/book/* |
web_application | *.skyscanner.net |
web_application | skyscanner.net/* |
web_application | partnerportal.skyscanner.net/* |
Scope Type | Scope Name |
---|---|
web_application | Corporate Email (*@skyscanner.net) |
Firebounty have crawled on 2018-11-28 the program Skyscanner on the platform Bugcrowd.
FireBounty © 2015-2024