Amazon Vulnerability Research Program
Amazon Vulnerability Research Program on HackerOne · HackerOne Active
Scope
At a glance
- Bounties: Yes
- Swag: Yes
- Managed by the platform: Yes
- Average first response: 0.4 days
- Average time to resolution: 156.5 days
In scope
*.amazon.ae*.amazon.ca*.amazon.cl*.amazon.cn*.amazon.co.jp*.amazon.co.uk*.amazon.co.za*.amazon.com*.amazon.com.au*.amazon.com.be*.amazon.com.br*.amazon.com.co*.amazon.com.mx*.amazon.com.ng*.amazon.com.tr*.amazon.de*.amazon.eg*.amazon.es*.amazon.fr*.amazon.in*.amazon.it*.amazon.nl*.amazon.pl*.amazon.sa*.amazon.se*.amazon.sg10573386871151746202126517091412762961031454725763147502157414783509151494755014149819703315321532191552455423157937226115922049071659883691
60 more assets on the official page.
Out of scope
"Contact Us" Functionality*.*a2z*.**.aws.**.devAWS and AWS customer assets are strictly out of scopeAmazon Web Services (AWS)Anything considered a non-prod assetAnything which redirects to AWSamazongames.comlearning.logistics.amazon.com
Imported from the public directory. Always confirm scope on the official program page before testing.