YWH YesWeHack LIVE
Alasco GmbH - Bug Bounty Program
€50 –€1,000
Open on YesWeHack ↗
- listed
- before tracking
- tracked since
- 2026-09-20
- managed triage
- no
4 targets in scope
| asset | type | bounty | max sev | seen |
|---|---|---|---|---|
api.alasco.de | api | · | · | 2026-09-20 |
app.alasco.de | domain | · | · | 2026-09-20 |
*.alasco.de | other | · | · | 2026-09-20 |
*.alasco.rocks | other | · | · | 2026-09-20 |
15 out of scope — black ICE, don't touch
Alasco will not provide access credentials to any system, not for testing and also not for issue validation.otherAll other domains or subdomains not listed in the above list of 'Scopes'.otherAttention: Third-party managed infrastructure (e.g. HubSpot, Salesforce, or other SaaS platforms) where Alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomain.otherHowever, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this program.otherPlease note that all non-authenticated areas of our systems are in scope for this program. This means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a reward.otheralasco.comotheralasco.deotherexplore.alasco.comotherexplore.alasco.deotherlp.alasco.comotherlp.alasco.deothersupport.alasco.comothersupport.alasco.deotherwww.alasco.comotherwww.alasco.deother
Change log
get alerts ↗No changes since we started tracking on 2026-09-20.