Bugcrowd · Bug Bounty

REA Group | realestate.com.au, realcommercial.com.au, property.com.au Bug Bounty Program

Complete guide to REA Group | realestate.com.au, realcommercial.com.au, property.com.au's bug bounty program on Bugcrowd. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

REA Group | realestate.com.au, realcommercial.com.au, property.com.au runs a bug bounty program on Bugcrowd with a maximum payout of $4,500. The program has 12 in-scope assets and is managed by Bugcrowd's triage team.

12
In-Scope Assets
$4,500
Max Payout

In-Scope Assets

AssetTypeMax SeverityEligible
rea-group.comWEBSITE
reastatic.netWEBSITE
*.api.id.realestate.com.auAPI
*.id.realestate.com.auWEBSITE
*.accounts.realestate.com.auWEBSITE
https://play.google.com/store/apps/details?id=au.com.realestate.appANDROID
https://apps.apple.com/au/app/realestate-com-au-property/id404667893IOS
*.realestate.com.auWEBSITE
https://www.realcommercial.com.au/WEBSITE
https://property.com.auWEBSITE
https://next.flatmates.com.auWEBSITE
https://api-next.flatmates.com.auAPI

Out-of-Scope Assets

  • *.email.rea-group.com
  • autodiscover.rea-group.com
  • garage.rea-group.com
  • help.enterprise.rea-group.com
  • help.rea-group.com
  • university.rea-group.com
  • analytics[.e2e].realestate.com.au
  • *.realestate.com.au/homeloans
  • homeloans.realestate.com.au
  • realestate.com.au/advice
  • https://www.realestate.com.au/insights/
  • realestate.com.au/lifestyle
  • https://www.realestate.com.au/advice/
  • realestate.com.au/podcasts
  • sasinator.realestate.com.au
  • smetrics.realestate.com.au
  • https://video.realestate.com.au/
  • https://help.realestate.com.au
  • *.propertypanel.realestate.com.au
  • realtair-sell.realestate.com.au

Tips for Hacking REA Group | realestate.com.au, realcommercial.com.au, property.com.au

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking REA Group | realestate.com.au, realcommercial.com.au, property.com.au?

Sign up on Bugcrowd, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does REA Group | realestate.com.au, realcommercial.com.au, property.com.au pay bounties?

Yes, REA Group | realestate.com.au, realcommercial.com.au, property.com.au offers monetary rewards for valid security vulnerabilities.

What types of vulnerabilities does REA Group | realestate.com.au, realcommercial.com.au, property.com.au accept?

REA Group | realestate.com.au, realcommercial.com.au, property.com.au accepts reports for vulnerabilities found in their 12 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.