PentestingHere
Log in Join

20 Minuten

20 Minuten on Bugcrowd · Bugcrowd Active

Official page

Scope

At a glance

  • Maximum payout: $5,000
  • Public disclosure: Not allowed
  • Managed by the platform: Yes
  • Safe harbour: Full

In scope

  • https://www.20min.ch
  • https://coral.20min.ch/
  • https://api.20min.ch/
  • https://videoplayer.20min.ch
  • https://partner-feeds.20min.ch
  • https://screenplayer.20min.ch
  • https://audio.20min.ch/

Out of scope

  • https://tgt.tamedia.ch
  • http://auth.20min.ch
  • https://cre-api.tamedia.ch
  • https://track.20min.ch
  • Social Media Links (older than 2 years)
  • Subdomain Takeover
  • DMARC, SPF, DKIM
  • https://*.connect.ringier.ch
  • *.onelog.ch
  • *.20min-tv.ch
  • *.newsnetz.tv
  • *.appuser.ch
  • *.iagentur.ch
  • *.streamboat.ch
  • *.streamboatserver.ch
  • Other Domains and Subdomains not specifically in scope

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback