Cyberlium

Bug › Module 3 › Lesson 2

BeginnerModule 3Lesson 2/5

In vs Out

In-scope vs out-of-scope lists protect strangers — classify assets for YOUR $SCOPE_HOST program.

15 min+40 XP3 quiz
Module progress2 of 5

Visual · bounty_in_vs_out

In vs out literacy. $SCOPE_HOST only. Original Cyberlium.

Opening

Professional programs spend pages on what is OUT. So will your notes.

In-scope assets are fair game under program rules — $SCOPE_HOST and explicitly listed relatives. Out-of-scope includes third-party SaaS, corporate infrastructure not listed, employee personal accounts, acquisitions not yet added, and wildcard exclusions. Misclassifying a CDN edge or staging domain causes report rejection and account risk. Cyberlium treats in/out classification as mandatory before recon. You will NOT assume all subdomains inherit scope without reading wildcard rules. Next: Rate Limits & Forbidden Actions.

1. In-scope confirmation checklist

Is the exact hostname listed or covered by an explicit wildcard rule? Is the asset tier (prod vs staging) included? Are mobile apps or APIs separately listed? If any answer is unclear, ask program — do not probe.

$SCOPE_HOST goes in the in-scope column only after passing this checklist.

Command guide

Try these commands — In-scope confirmation checklist

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

Out of scope — third-party CDN, employee emails, DoS Rate limits — program-specific

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl

macOS: Built-in

Windows: Built-in (PowerShell: Invoke-WebRequest)

═══ LINUX / macOS ═══

Command — copy this

grep OUT_OF_SCOPE "$HOME/cyberlium-lab/t20-scope.env" 2>/dev/null || echo 'Create t20-scope.env in 3-4'
curl -sS -I --max-time 5 https://httpbin.org/status/200 | head -8

Primary tools to practice this lesson: grep, curl. Reference sites: Out of scope; Rate limits. Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Out-of-scope patterns to recognize

Third-party checkout, support chat widgets, marketing iframes, 'out of scope' labels on subdomains, and 'third-party services' clauses. Discovery of an interesting host outside scope → note and stop.

Classmate deploy URLs, café sites, and dorm LANs are always out — not bounty scope puzzles.

3. When discovery blurs the line

New subdomain found during authorized recon on $SCOPE_HOST? Check scope wildcards and out-of-scope lists. Still unclear → program question, no probe until answered.

Ship: two-column table — three in-scope and three out-of-scope examples for YOUR program. Next: Rate Limits & Forbidden Actions.

4. What you ship: in vs out table for $SCOPE_HOST

Two columns: in-scope and out-of-scope examples. $SCOPE_HOST confirmed in. NEVER random sites. chmod 600.

5. What you record before the next lesson

Date. In/out table. $SCOPE_HOST in-scope confirmed. File t20-m03-l02-in-vs-out.txt chmod 600.

6. Wrong vs right: random sites vs in-scope program

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Treat all *.company.com as in without reading exclusions. Probe payment gateway because it linked from $SCOPE_HOST.

  • Right

    Write in/out table for YOUR program. Next: Rate Limits & Forbidden Actions.

Mission: classify in vs out for YOUR program

1) List three in-scope assets including $SCOPE_HOST. 2) List three out-of-scope categories from policy. 3) chmod 600. Stop when asset fails in-scope checklist.

Stuck? Ask Cyberlium AI Mentor

When unsure, ask — guessing out-of-scope wrong ends careers.

Knowledge Check

1

APPLY: You find a subdomain during $SCOPE_HOST recon not clearly listed. You:

Multiple choice

Knowledge Check

2

APPLY: True or False: Third-party payment gateways are usually in scope by default.

True or False

Knowledge Check

3

APPLY: Classmate deploy URLs are:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)