HackerOne · VDP

Global Payments Vulnerability Disclosure Program

Complete guide to Global Payments's vulnerability disclosure program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Global Payments runs a vulnerability disclosure program on HackerOne. The program has 37 in-scope assets and is managed by HackerOne's triage team.

37
In-Scope Assets
8h
Avg Response
93%
Efficiency
8d
Avg Resolve

In-Scope Assets

AssetTypeMax SeverityEligible
Active NetworksOTHERCriticalNo Bounty
Analytics & Customer Engagement (ACE)SOURCE_CODECriticalNo Bounty
Chargeback HelpOTHERCriticalNo Bounty
Comercia Global Payments OTHERCriticalNo Bounty
ECSIOTHERCriticalNo Bounty
EVO Payments, Inc. OTHERCriticalNo Bounty
EzidebitOTHERCriticalNo Bounty
GP AUNZOTHERCriticalNo Bounty
GP IntegratedOTHERCriticalNo Bounty
GP Integrated - PayGatewayOTHERCriticalNo Bounty
GP eComOTHERCriticalNo Bounty
GPEOTHERCriticalNo Bounty
Global Payments IncOTHERCriticalNo Bounty
Global Payments IntegratedOTHERCriticalNo Bounty
Greater GivingOTHERCriticalNo Bounty
Heartland Payment SystemsOTHERCriticalNo Bounty
Heartland Restaurant / Retail / Payroll / Human Capital Management (Get Hired)OTHERCriticalNo Bounty
MerchantWareOTHERCriticalNo Bounty
MicropaymentsOTHERCriticalNo Bounty
MineralTreeOTHERCriticalNo Bounty
My School BucksOTHERCriticalNo Bounty
NextepOTHERCriticalNo Bounty
OpenEdgeOTHERCriticalNo Bounty
SentralOTHERCriticalNo Bounty
StormanOTHERCriticalNo Bounty
TSYS OTHERCriticalNo Bounty
TouchNetOTHERCriticalNo Bounty
Vendara - GatewayOTHERCriticalNo Bounty
Vendara - JarvisOTHERCriticalNo Bounty
Vendara - Merchant PortalOTHERCriticalNo Bounty
ZegoOTHERCriticalNo Bounty
bleepplc.co.ukURLCriticalNo Bounty
developer.globalpay.comURLCriticalNo Bounty
eWayOTHERCriticalNo Bounty
http://cloud-sbox.storman.comURLCriticalNo Bounty
http://portal-staging.storman.comURLCriticalNo Bounty
pcamerica.comURLCriticalNo Bounty

Out-of-Scope Assets

  • Globalpaymentsinc.com and Globalpayments.com - OUT OF SCOPE
  • Leaked Credentials
  • Xenial (Xenial)
  • remotesupport.heartland.us

Tips for Hacking Global Payments

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Global Payments?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Global Payments pay bounties?

No, Global Payments runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.

What types of vulnerabilities does Global Payments accept?

Global Payments accepts reports for vulnerabilities found in their 37 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.