Program Overview
Mars runs a vulnerability disclosure program on HackerOne. The program has 110 in-scope assets and is managed by HackerOne's triage team.
In-Scope Assets
| Asset | Type | Max Severity | Eligible |
|---|---|---|---|
| *.banfield.com | WILDCARD | Critical | No Bounty |
| *.banfieldassets.com | WILDCARD | Critical | No Bounty |
| *.bibliotecarc.cl | WILDCARD | Critical | No Bounty |
| *.bluepearlvet.com | WILDCARD | Critical | No Bounty |
| *.cloud-effem.com | WILDCARD | Critical | No Bounty |
| *.coroapremiada.com.br | WILDCARD | Critical | No Bounty |
| *.dovechocolate.com | WILDCARD | Critical | No Bounty |
| *.effem.com | WILDCARD | Critical | No Bounty |
| *.eukanuba-gt.com | WILDCARD | Critical | No Bounty |
| *.eukanuba.com | WILDCARD | Critical | No Bounty |
| *.eukanuba.com.ar | WILDCARD | Critical | No Bounty |
| *.eukanubasportingdog.com | WILDCARD | Critical | No Bounty |
| *.extragum.com | WILDCARD | Critical | No Bounty |
| *.findroyalcanin.com | WILDCARD | Critical | No Bounty |
| *.hnlp.jp | WILDCARD | Critical | No Bounty |
| *.individualis.com | WILDCARD | Critical | No Bounty |
| *.indsight-royalcanin.com | WILDCARD | Critical | No Bounty |
| *.jornadasroyalcanin.com.ar | WILDCARD | Critical | No Bounty |
| *.mars-dna.com | WILDCARD | Critical | No Bounty |
| *.mars.com | WILDCARD | Critical | No Bounty |
| *.marschocolate.com | WILDCARD | Critical | No Bounty |
| *.meetmynewpet.com | WILDCARD | Critical | No Bounty |
| *.miroyalcanin.cl | WILDCARD | Critical | No Bounty |
| *.miroyalcanin.com.ar | WILDCARD | Critical | No Bounty |
| *.mivetshop.com.ar | WILDCARD | Critical | No Bounty |
| *.mms.com | WILDCARD | Critical | No Bounty |
| *.momentosroyalcanin.com | WILDCARD | Critical | No Bounty |
| *.moncse-royalcanin-siege.com | WILDCARD | Critical | No Bounty |
| *.monespaceeleveur.fr | WILDCARD | Critical | No Bounty |
| *.monespacetoiletteur.com | WILDCARD | Critical | No Bounty |
| *.monespaceveto.com | WILDCARD | Critical | No Bounty |
| *.mycat2vet.my | WILDCARD | Critical | No Bounty |
| *.myroyalcanin.bg | WILDCARD | Critical | No Bounty |
| *.myroyalcanin.gr | WILDCARD | Critical | No Bounty |
| *.myroyalcanin.hr | WILDCARD | Critical | No Bounty |
| *.myroyalcanin.hu | WILDCARD | Critical | No Bounty |
| *.myroyalcanin.ro | WILDCARD | Critical | No Bounty |
| *.myroyalcanin.si | WILDCARD | Critical | No Bounty |
| *.orbitgum.com | WILDCARD | Critical | No Bounty |
| *.pedigree.com | WILDCARD | Critical | No Bounty |
| *.plataformaurinary.com | WILDCARD | Critical | No Bounty |
| *.puntosroyaltyrc.com.co | WILDCARD | Critical | No Bounty |
| *.rcjapan.jp | WILDCARD | Critical | No Bounty |
| *.rcpracownik.pl | WILDCARD | Critical | No Bounty |
| *.royal-canin.by | WILDCARD | Critical | No Bounty |
| *.royal-canin.co.kr | WILDCARD | Critical | No Bounty |
| *.royal-canin.co.za | WILDCARD | Critical | No Bounty |
| *.royal-canin.com | WILDCARD | Critical | No Bounty |
| *.royalcanin-cp.jp | WILDCARD | Critical | No Bounty |
| *.royalcanin-pethealthday.com | WILDCARD | Critical | No Bounty |
Showing 50 of 110 in-scope assets. View all on HackerOne.
Tips for Hacking Mars
- Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
- Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
- Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
- Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
- Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.
Frequently Asked Questions
How do I start hacking Mars?
Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.
Does Mars pay bounties?
No, Mars runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.
What types of vulnerabilities does Mars accept?
Mars accepts reports for vulnerabilities found in their 110 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.