Bug › Module 3 › Lesson 2
In vs Out
In-scope vs out-of-scope lists protect strangers — classify assets for YOUR $SCOPE_HOST program.
Visual · bounty_in_vs_out
In vs out literacy. $SCOPE_HOST only. Original Cyberlium.
Opening
Professional programs spend pages on what is OUT. So will your notes.
In-scope assets are fair game under program rules — $SCOPE_HOST and explicitly listed relatives. Out-of-scope includes third-party SaaS, corporate infrastructure not listed, employee personal accounts, acquisitions not yet added, and wildcard exclusions. Misclassifying a CDN edge or staging domain causes report rejection and account risk. Cyberlium treats in/out classification as mandatory before recon. You will NOT assume all subdomains inherit scope without reading wildcard rules. Next: Rate Limits & Forbidden Actions.
1. In-scope confirmation checklist
Is the exact hostname listed or covered by an explicit wildcard rule? Is the asset tier (prod vs staging) included? Are mobile apps or APIs separately listed? If any answer is unclear, ask program — do not probe.
$SCOPE_HOST goes in the in-scope column only after passing this checklist.
Command guide
Try these commands — In-scope confirmation checklist
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Out of scope — third-party CDN, employee emails, DoS Rate limits — program-specific
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
grep OUT_OF_SCOPE "$HOME/cyberlium-lab/t20-scope.env" 2>/dev/null || echo 'Create t20-scope.env in 3-4' curl -sS -I --max-time 5 https://httpbin.org/status/200 | head -8
Primary tools to practice this lesson: grep, curl. Reference sites: Out of scope; Rate limits. Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Out-of-scope patterns to recognize
Third-party checkout, support chat widgets, marketing iframes, 'out of scope' labels on subdomains, and 'third-party services' clauses. Discovery of an interesting host outside scope → note and stop.
Classmate deploy URLs, café sites, and dorm LANs are always out — not bounty scope puzzles.
3. When discovery blurs the line
New subdomain found during authorized recon on $SCOPE_HOST? Check scope wildcards and out-of-scope lists. Still unclear → program question, no probe until answered.
Ship: two-column table — three in-scope and three out-of-scope examples for YOUR program. Next: Rate Limits & Forbidden Actions.
4. What you ship: in vs out table for $SCOPE_HOST
Two columns: in-scope and out-of-scope examples. $SCOPE_HOST confirmed in. NEVER random sites. chmod 600.
5. What you record before the next lesson
Date. In/out table. $SCOPE_HOST in-scope confirmed. File t20-m03-l02-in-vs-out.txt chmod 600.
6. Wrong vs right: random sites vs in-scope program
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Treat all *.company.com as in without reading exclusions. Probe payment gateway because it linked from $SCOPE_HOST.
Right
Write in/out table for YOUR program. Next: Rate Limits & Forbidden Actions.
Mission: classify in vs out for YOUR program
1) List three in-scope assets including $SCOPE_HOST. 2) List three out-of-scope categories from policy. 3) chmod 600. Stop when asset fails in-scope checklist.
Stuck? Ask Cyberlium AI Mentor
When unsure, ask — guessing out-of-scope wrong ends careers.
Knowledge Check
APPLY: You find a subdomain during $SCOPE_HOST recon not clearly listed. You:
Multiple choice
Knowledge Check
APPLY: True or False: Third-party payment gateways are usually in scope by default.
True or False
Knowledge Check
APPLY: Classmate deploy URLs are:
Multiple choice