MoveIt is an independent two-wheeler taxi platform serving the Philippines.
Please note that since this is a third-party application, most reports will typically be marked with a maximum of medium-severity (especially due to modifications not controlled by the Grab team, but by the vendor). In cases where the vulnerability is severe enough, such as an RCE, mass retrieval of personal information etc, we will review them on a case-by-case basis and will reward a bounty accordingly at our discretion.
*.taralite.com has been rebranded as OVO Finansial
OVO iOS application
https://apps.apple.com/ID/app/id1142114207
Staging/Development/UAT environments are considered out-of-scope, such as:
- *.byte-stack.net
- *.dududev
- *.uat-ovo.net
and other assets that might not be explicitly listed.
**What it does:** Grab iOS and Android apps communicate with this service while you use Grab specifically for newer payment features. This endpoint acts as an API gateway proxy to all of our services. This API exposes the largest attack surface of any service here at GrabPay.
**What to look for:** Much like our external API, `api.grabpay.com` is a RESTful API performed over HTTPS requests. The best way to hunt for bugs here is to use your own auth token via the `X-mts-ssid` header and look for authorization and access control issues, business logic and etc. Please keep in mind that you should only ever perform this testing against accounts you own, accessing any data not owned by you can result in disqualification.
**What it runs on:** Golang / Java
Staging/Development/UAT environments are considered out-of-scope, such as:
- *.byte-stack.net
- *.dududev
- *.uat-ovo.net
and other assets that might not be explicitly listed
Please note that since this is a third-party application, most reports will typically be marked with a maximum of medium-severity (especially due to modifications not controlled by the Grab team, but by the vendor). In cases where the vulnerability is severe enough, such as an RCE, mass retrieval of personal information etc, we will review them on a case-by-case basis and will reward a bounty accordingly at our discretion.
Grab Driver app for Huawei Devices(using HMS)
https://appgallery.huawei.com/#/app/C103149579
In-scope only in November to December 2022 Promotion
In-scope only in November to December 2022 Promotion
MoveIt is an independent two-wheeler taxi platform serving the Philippines.
**Please note: This asset is only in-scope during the March 4 to April 3 2023 Grab promotion.**
HungryGoWhere is a food discovery platform that helps users explore dining options, reviews, and deals, primarily in Singapore.
Grab (iOS)
* Eligible for updated mobile Apps bounty rewards offering (up to $15,000 for a Critical vulnerability)
Staging/Development/UAT environments are considered out-of-scope, such as:
- *.byte-stack.net
- *.dududev
- *.uat-ovo.net
and other assets that might not be explicitly listed.
**What it does:** Grab iOS and Android apps communicate with this service while you use Grab. This endpoint acts as an API gateway proxy to all of our services. This API exposes the largest attack surface of any service here at Grab.
**What to look for:** Much like our external API, p.grabtaxi.com is a RESTful API performed over certificate-pinned HTTPS requests. The best way to hunt for bugs here is to use your own auth token via the X-mts-ssid header and look for authorization and access control issues, user enumeration, business logic etc. Please keep in mind that you should only ever perform this testing against accounts you own, failure to do so could result in ban from the program, which nobody wants!.
**What it runs on:** Golang
OVO's Android App:
https://play.google.com/store/apps/details?id=ovo.id
Staging/Development/UAT environments are considered out-of-scope, such as:
*.byte-stack.net
*.dududev
*.uat-ovo.net and other assets that might not be explicitly listed.
GrabPay Merchant
GrabPay Merchant
Grab Superapp for Huawei Devices(using HMS)
https://appgallery.huawei.com/#/app/C100447517
Grab Driver
* Eligible for updated mobile Apps bounty rewards offering (up to $15,000 for a Critical vulnerability)
Grab (Android)
* Eligible for updated mobile Apps bounty rewards offering (up to $15,000 for a Critical vulnerability)
Grab Driver
* Eligible for updated mobile Apps bounty rewards offering (up to $15,000 for a Critical vulnerability)