PentestingHere
Log in Join

Amazon Vulnerability Research Program

Amazon Vulnerability Research Program on HackerOne · HackerOne Active

Official page

Scope

At a glance

  • Bounties: Yes
  • Swag: Yes
  • Managed by the platform: Yes
  • Average first response: 0.4 days
  • Average time to resolution: 156.5 days

In scope

  • *.amazon.ae
  • *.amazon.ca
  • *.amazon.cl
  • *.amazon.cn
  • *.amazon.co.jp
  • *.amazon.co.uk
  • *.amazon.co.za
  • *.amazon.com
  • *.amazon.com.au
  • *.amazon.com.be
  • *.amazon.com.br
  • *.amazon.com.co
  • *.amazon.com.mx
  • *.amazon.com.ng
  • *.amazon.com.tr
  • *.amazon.de
  • *.amazon.eg
  • *.amazon.es
  • *.amazon.fr
  • *.amazon.in
  • *.amazon.it
  • *.amazon.nl
  • *.amazon.pl
  • *.amazon.sa
  • *.amazon.se
  • *.amazon.sg
  • 1057338687
  • 1151746202
  • 1265170914
  • 1276296103
  • 1454725763
  • 1475021574
  • 1478350915
  • 1494755014
  • 1498197033
  • 1532153219
  • 1552455423
  • 1579372261
  • 1592204907
  • 1659883691

60 more assets on the official page.

Out of scope

  • "Contact Us" Functionality
  • *.*a2z*.*
  • *.aws.*
  • *.dev
  • AWS and AWS customer assets are strictly out of scope
  • Amazon Web Services (AWS)
  • Anything considered a non-prod asset
  • Anything which redirects to AWS
  • amazongames.com
  • learning.logistics.amazon.com

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback