Oasis Protocol Foundation HackerOne


Target Policy
https://hackerone.com/oasis_protocol_foundation?type=team
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • https://github.com/oasisprotocol/oasis-wallet-ext
    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/oasis-core

    Blockchain Software

    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/ed25519
    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/curve25519-voi

    Ed25519/Sr25519 implementation.

    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/oasis-wallet-web
    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/deoxysii
    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/deoxysii-rust
    SOURCE_CODE
    critical
  • https://github.com/oasisprotocol/oasis-sdk

    Blockchain Software

    SOURCE_CODE
    critical
  • wallet.oasis.io
    URL
    critical
  • status.oasis.io
    URL
    critical
  • http://rosetta.oasis.dev/api/mainnet
    URL
    critical
  • http://emerald.oasis.dev
    URL
    critical
  • github.com/oasisprotocol/explorer
    SOURCE_CODE
    critical
  • http://sapphire.oasis.io
    URL
    critical
  • http://grpc.oasis.dev
    URL
    critical
  • Not in Scope

    * Vulnerabilities in SGX hardware that cannot be fixed with software refactors
    * The Oasis Protocol Website (oasisprotocol.org)
    * Layer 3/Layer 4 DoS attacks on testnet infrastructure
    * Social Engineering Attacks on Oasis Protocol Foundation staff
    * Operational vulnerabilities related to any node operator of a testnet or the mainnet

    ###Domains
    * *.oasisprotocol.org

    OTHER
    none
Target Scope Domains
  • emerald.oasis.dev
  • grpc.oasis.dev
  • rosetta.oasis.dev
  • sapphire.oasis.io
  • status.oasis.io
  • wallet.oasis.io
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allkxss
1 year, 1 month ago
Finished
  • Fleet: allkxss
  • Duration: 17.67 Minutes
  • Finished: 1 year, 1 month ago