Lob

target_in_scope

asset_identifier asset_type availability requirement confidentiality requirement eligible for bounty eligible for submission integrity requirement max_severity
address-autocomplete.lob.com URL critical
api.lob.com URL high high high critical
arcade.lob.com URL critical
blog.lob.com URL none none none none
dashboard.lob.com URL high high high critical
docs.lob.com URL none none none none
dora.lob.com URL critical
lob-assets.com URL critical
lob.com URL critical
mock.lob.com URL none none none none
partners.lob.com URL critical
pizza-planet.lob.com URL critical
redshift.lob.com URL critical
sftp.lob.com URL critical
signal.lob.com URL critical
usps-sftp.lob.com URL critical
vpn.lob.com URL critical
woody.lob.com URL critical
wp.lob.com URL none none none none
www.lob.com URL high high high critical

target_out_of_scope

asset_identifier asset_type availability requirement confidentiality requirement eligible for bounty eligible for submission integrity requirement max_severity
Comments form on wp.lob.com & lob.com/blog blog posts OTHER none
Please do not submit comments with payloads on our blog posts.
cio.lob.com URL none
email.lob.com URL none
get.lob.com URL none
go.lob.com URL none
Please do not submit any forms on this domain.
https://lob.com/careers/*/apply URL none
Please do not submit the job application form on this page.
https://lob.com/support/contact URL none
Please do not submit the support form on this page.
status.lob.com URL none
support.lob.com URL none
https://lob.com/careers/* URL none
Please do not test against or submit any job applications.
wp.lob.com and lob.com/blog OTHER none
library.lob.com URL none