Eternal icon Eternal HackerOne


Target Policy
https://hackerone.com/eternal?type=team
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • winecellar.zomato.com
    URL
    critical
  • *.insider.in
    WILDCARD
    critical
  • Blinkit, Bistro and Hyperpure assets (in scope)
    OTHER
    critical
  • *.tktnew.com
    WILDCARD
    critical
  • com.blinkit.bistro

    Bistro by Blinkit: A mobile app offering instant food delivery

    https://play.google.com/store/apps/details?id=com.blinkit.bistro

    GOOGLE_PLAY_APP_ID
    critical
  • com.application.zomato
    GOOGLE_PLAY_APP_ID
    critical
  • *.zomans.com

    This domain is mainly used for internal applications that are hosted in AWS. Our area of interest is any issue that can potentially give anyone unrestricted access or expose internal or confidential data.

    WILDCARD
    critical
  • api2.grofers.com
    URL
    critical
  • *.edition.in
    WILDCARD
    critical
  • *.zomato.com
    WILDCARD
    critical
  • *.district.in
    WILDCARD
    critical
  • All Zomato Assets (Other than BlinkIT & Hyperpure)
    OTHER
    critical
  • 6670203019

    Bistro by Blinkit: A mobile app offering instant food delivery

    https://apps.apple.com/in/app/bistro-food-in-minutes/id6670203019

    APPLE_STORE_APP_ID
    critical
  • *.hyperpure.com
    WILDCARD
    critical
  • http://*.grofer.io
    WILDCARD
    critical
  • 434613896

    Zomato: Food Delivery & Dining

    APPLE_STORE_APP_ID
    critical
  • *.runnr.in
    WILDCARD
    critical
  • http://*.grofers.com
    WILDCARD
    critical
  • com.grofers.customerapp

    Blinkit's Customer Android App:
    https://play.google.com/store/apps/details?id=com.grofers.customerapp

    GOOGLE_PLAY_APP_ID
    critical
  • BlinkIT, Hyperpure assets (in scope)
    OTHER
    critical
  • api.grofers.com
    URL
    critical
  • blinkit.com
    URL
    critical
  • All Assets (other than Blinkit)

    Bounty table header

    OTHER
    critical
  • All District Assets (Other than Zomato, BlinkIT & Hyperpure)
    OTHER
    critical
  • *.ticketnew.com
    WILDCARD
    critical
  • bistro-api.blinkit.com
    URL
    critical
  • *.zdev.net
    WILDCARD
    critical
Target Scope Domains
  • api.grofers.com
  • api2.grofers.com
  • bistro-api.blinkit.com
  • blinkit.com
  • district.in
  • edition.in
  • grofer.io
  • grofers.com
  • hyperpure.com
  • insider.in
  • runnr.in
  • ticketnew.com
  • tktnew.com
  • winecellar.zomato.com
  • zdev.net
  • zomans.com
  • zomato.com
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allkxss
1 week, 6 days ago
Finished
  • Fleet: allkxss
  • Duration: 23 Seconds
  • Finished: 1 week, 6 days ago