HackerOne · Bug Bounty

Flutter UK&I Bug Bounty Program

Complete guide to Flutter UK&I's bug bounty program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Flutter UK&I runs a bug bounty program on HackerOne. The program has 42 in-scope assets and is managed by HackerOne's triage team.

42
In-Scope Assets
6h
Avg Response
98%
Efficiency
2d
Avg Bounty Time

In-Scope Assets

AssetTypeMax SeverityEligible
*.betfair.comWILDCARDCriticalBounty
*.betfair.esWILDCARDCriticalBounty
*.betfair.itWILDCARDCriticalBounty
*.betfair.roWILDCARDCriticalBounty
*.betfair.seWILDCARDCriticalBounty
*.betsharedservices.ioWILDCARDCriticalBounty
*.betviewapi.comWILDCARDCriticalBounty
*.dibz.co.ukWILDCARDCriticalBounty
*.msgsvc.ioWILDCARDCriticalBounty
*.operationstechnology.ioWILDCARDCriticalBounty
*.paddypartners.comWILDCARDCriticalBounty
*.paddypower.comWILDCARDCriticalBounty
*.paddypower.itWILDCARDCriticalBounty
*.platformservices.ioWILDCARDCriticalBounty
*.ppbdev.comWILDCARDMediumBounty
*.sbgcdn.comWILDCARDCriticalBounty
*.sbgcore.comWILDCARDCriticalBounty
*.sbgorigin.comWILDCARDCriticalBounty
*.sbgservices.comWILDCARDCriticalBounty
*.sbgtest.netWILDCARDCriticalBounty
*.securityservices.ioWILDCARDCriticalBounty
*.skybet.co.ukWILDCARDCriticalBounty
*.skybet.comWILDCARDCriticalBounty
*.skybet.netWILDCARDCriticalBounty
*.skybetservices.comWILDCARDCriticalBounty
*.skybettest.netWILDCARDCriticalBounty
*.skybettingandgaming.comWILDCARDCriticalBounty
*.skybettingandgaming.designWILDCARDCriticalBounty
*.skybettingandgaming.infoWILDCARDCriticalBounty
*.skybingo.comWILDCARDCriticalBounty
*.skycasino.comWILDCARDCriticalBounty
*.skygamingcontent.comWILDCARDCriticalBounty
*.skypoker.comWILDCARDCriticalBounty
*.skyvegas.comWILDCARDCriticalBounty
*.sportinglife.comWILDCARDCriticalBounty
https://play.google.com/store/apps/dev?id=5503565801970655430&gl=gbGOOGLE_PLAY_APP_IDCriticalBounty
https://play.google.com/store/apps/dev?id=8912907283039023448&gl=GBGOOGLE_PLAY_APP_IDCriticalBounty
https://play.google.com/store/apps/dev?id=9151483005769461618&gl=GBGOOGLE_PLAY_APP_IDCriticalBounty
https://play.google.com/store/apps/developer?id=Sky+Betting+and+Gaming+Apps&gl=ukGOOGLE_PLAY_APP_IDCriticalBounty
itv7.itv.comURLCriticalBounty
rafflee.co.ukURLCriticalBounty
super6.skysports.comURLCriticalBounty

Out-of-Scope Assets

  • *.betfair.com.au
  • *.email.skybet.com
  • *.s6.sbgservices.com
  • *.sbagmail.skybettingandgaming.com
  • *.sbg.life
  • *.sbga.me
  • *.sbgcolab.com
  • *.sbgdataintl.com
  • *.sbggraduates.com
  • *.sbgmail.skybettingandgaming.com
  • *.sbgpeople.com
  • *.sbpartner.it
  • *.skybet-it.info
  • *.skybet.de
  • *.skybet.it
  • *.skybetcareers.com
  • *.skybetchiusuraconto.it
  • *.skybetgraduates.com
  • *.skybetpartner.de
  • *.skybettingandgamingresearch.com

Tips for Hacking Flutter UK&I

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Flutter UK&I?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Flutter UK&I pay bounties?

Yes, Flutter UK&I offers monetary rewards for valid security vulnerabilities.

What types of vulnerabilities does Flutter UK&I accept?

Flutter UK&I accepts reports for vulnerabilities found in their 42 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.