govtech-vrp

YesWeHackView on YesWeHack
RawAI Enhanced
47
In Scope
34
Out of Scope
In-Scope Assets (47)
AssetCategoryBountyQuick Links
A1-6.AKAM.NETOTHERYes-
A2-65.AKAM.NETOTHERYes-
A20-66.AKAM.NETOTHERYes-
A3-67.AKAM.NETOTHERYes-
A8-64.AKAM.NETOTHERYes-
A9-65.AKAM.NETOTHERYes-
NS10.GDNSDEF.COMOTHERYes-
NS12.GDNSEC.COMOTHERYes-
NS3.GDNSEC.COMOTHERYes-
NS7.GDNSDEF.COMOTHERYes-
NS9.GDNSEC.COMOTHERYes-
http://www.cdlens.moh.gov.sg/cdlensURLYes
https://api.id.gov.sgURLYes
https://api.myinfo.gov.sgURLYes
https://app.eservice.eld.gov.sg/Voter/URLYes
https://apps.apple.com/app/singpass/id1340660807IOSYes-
https://bio-api.singpass.gov.sgURLYes
https://bio-stream.singpass.gov.sgURLYes
https://mohalert.moh.gov.sgURLYes
https://mytax.iras.gov.sg/ESVWeb/default.aspxURLYes
https://ntf.singpass.gov.sgURLYes
https://play.google.com/store/apps/details?id=sg.ndi.spANDROIDYes
https://portal.nehr.sgURLYes
https://register.id.gov.sgURLYes
https://saml.singpass.gov.sgURLYes
https://service2.mom.gov.sg/cpcspsso/URLYes
https://service2.mom.gov.sg/spcspsso/URLYes
https://service2.mom.gov.sg/workpass/ep/URLYes
https://service2.mom.gov.sg/workpass/sat/URLYes
https://service2.mom.gov.sg/workpass/whp/URLYes
https://service2.mom.gov.sg/workpass/whvp/URLYes
https://vrl.lta.gov.sgURLYes
https://www.corppass.gov.sgURLYes
https://www.cpf.gov.sg/api/assets/URLYes
https://www.cpf.gov.sg/bin/URLYes
https://www.cpf.gov.sg/content/URLYes
https://www.cpf.gov.sg/crpsonline/URLYes
https://www.cpf.gov.sg/employer/URLYes
https://www.cpf.gov.sg/eservices/URLYes
https://www.cpf.gov.sg/etc.clientlibs/URLYes
https://www.cpf.gov.sg/etc/URLYes
https://www.cpf.gov.sg/libs/URLYes
https://www.cpf.gov.sg/member/URLYes
https://www.eld.gov.sgURLYes
https://www.singpass.gov.sgURLYes
https://www.tradenet.gov.sgURLYes
https://www.vendors.gov.sgURLYes
Out-of-Scope Assets (34)
AssetCategoryBounty
2FA OTP for digital services is out of scope for vrl.lta.gov.sgOTHERYes
All Relying Parties (real entities/businesses) are out of scope from https://api.myinfo.gov.sg/OTHERYes
All domains or subdomains not listed in the above list of 'Scopes'OTHERYes
Any Open Redirect vulnerability that is used as part of Singpass or Corppass SAML integration is out of scope - https://saml.singpass.gov.sgOTHERYes
Any digital services that do not belong to vrl.lta.gov.sg domain is out of scopeOTHERYes
Candidates Services under app.eservice.eld.gov.sgOTHERYes
Domain/subdomain takeover is currently out of scope for GovTech DNS FQDNOTHERYes
ESA functions not in-scope (using netrust token) for vrl.lta.gov.sgOTHERYes
Message Hub Module from https://www.tradenet.gov.sg/OTHERYes
Testing of the payment portal is out of scope for vrl.lta.gov.sgOTHERYes
Uploading of the training record into the system, as the data will be used by other dependency system on service2.mom.gov.sgOTHERYes
https://*.wogaa.sg/OTHERYes
https://auth.nehr.sg/OTHERYes
https://c.go-mpulse.net/OTHERYes
https://elis.moh.gov.sg/OTHERYes
https://halp.moh.gov.sg/OTHERYes
https://housing.cpf.gov.sg/OTHERYes
https://onemotoring.lta.gov.sgOTHERYes
https://portal.nehr.sg/reports/OTHERYes
https://prs.moh.gov.sg/OTHERYes
https://s.go-mpulse.net/OTHERYes
https://smsgw.saasconnect.com/obh/SendSMSLegacyBCOTHERYes
https://sso-c.moh.gov.sg/esso/oidc/authorizeOTHERYes
https://www.asean-ssa.org/OTHERYes
https://www.cpf.gov.sg/caye/OTHERYes
https://www.customs.gov.sg/OTHERYes
https://www.google-analytics.com/OTHERYes
https://www.govpayouts.gov.sgOTHERYes
https://www.singpass.gov.sg/mainOTHERYes
https://www.singpass.gov.sg/myinfobusinessOTHERYes
https://www.tradenet.gov.sg/tradenet/portal/resetrequestOTHERYes
https://www.vcc.bizfile.gov.sg/OTHERYes
https://www.youtube.com/OTHERYes
https://www2.cpf.gov.sg/OTHERYes
Scope Changes (81)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://www.cpf.gov.sg/binURLIn Scope18:33
Addedhttps://www.singpass.gov.sgURLIn Scope18:33
Addedhttps://saml.singpass.gov.sgURLIn Scope18:33
Addedhttps://bio-stream.singpass.gov.sgURLIn Scope18:33
Addedhttps://bio-api.singpass.gov.sgURLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=sg.ndi.spANDROIDIn Scope18:33
Addedhttps://apps.apple.com/app/singpass/id1340660807IOSIn Scope18:33
Addedhttps://api.myinfo.gov.sgURLIn Scope18:33
Addedhttps://www.corppass.gov.sgURLIn Scope18:33
Addedhttps://service2.mom.gov.sg/workpass/satURLIn Scope18:33
Addedhttps://service2.mom.gov.sg/workpass/whpURLIn Scope18:33
Addedhttps://service2.mom.gov.sg/workpass/whvpURLIn Scope18:33
Addedhttps://service2.mom.gov.sg/workpass/epURLIn Scope18:33
Addedhttps://service2.mom.gov.sg/spcspssoURLIn Scope18:33
Addedhttps://service2.mom.gov.sg/cpcspssoURLIn Scope18:33
Addedhttps://www.vendors.gov.sgURLIn Scope18:33
Addedhttps://www.eld.gov.sgURLIn Scope18:33
Addedhttps://app.eservice.eld.gov.sg/VoterURLIn Scope18:33
Addedhttps://ntf.singpass.gov.sgURLIn Scope18:33
Addedhttps://register.id.gov.sgURLIn Scope18:33
Addedhttps://api.id.gov.sgURLIn Scope18:33
Addedhttps://vrl.lta.gov.sgURLIn Scope18:33
Addedhttp://www.cdlens.moh.gov.sg/cdlensURLIn Scope18:33
Addedhttps://mohalert.moh.gov.sgURLIn Scope18:33
Addedhttps://portal.nehr.sgURLIn Scope18:33
Addedhttps://mytax.iras.gov.sg/ESVWeb/default.aspxURLIn Scope18:33
Addedhttps://www.tradenet.gov.sgURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/memberURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/crpsonlineURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/employerURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/eservicesURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/etcURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/libsURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/api/assetsURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/etc.clientlibsURLIn Scope18:33
Addedhttps://www.cpf.gov.sg/contentURLIn Scope18:33
Addedns12.gdnsec.comOTHERIn Scope18:33
Addedns9.gdnsec.comOTHERIn Scope18:33
Addedns10.gdnsdef.comOTHERIn Scope18:33
Addedns3.gdnsec.comOTHERIn Scope18:33
Addedns7.gdnsdef.comOTHERIn Scope18:33
Addeda1-6.akam.netOTHERIn Scope18:33
Addeda20-66.akam.netOTHERIn Scope18:33
Addeda9-65.akam.netOTHERIn Scope18:33
Addeda8-64.akam.netOTHERIn Scope18:33
Addeda3-67.akam.netOTHERIn Scope18:33
Addeda2-65.akam.netOTHERIn Scope18:33
Addedall domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope18:33
Addedhttps://www.singpass.gov.sg/mainOTHEROut of Scope18:33
Addedhttps://www.singpass.gov.sg/myinfobusinessOTHEROut of Scope18:33
Addedcandidates services under app.eservice.eld.gov.sgOTHEROut of Scope18:33
Addedall relying parties (real entities/businesses) are out of scope from https://api.myinfo.gov.sgOTHEROut of Scope18:33
Addedany open redirect vulnerability that is used as part of singpass or corppass saml integration is out of scope - https://saml.singpass.gov.sgOTHEROut of Scope18:33
Addeddomain/subdomain takeover is currently out of scope for govtech dns fqdnOTHEROut of Scope18:33
Addedhttps://onemotoring.lta.gov.sgOTHEROut of Scope18:33
Addedany digital services that do not belong to vrl.lta.gov.sg domain is out of scopeOTHEROut of Scope18:33
Added2fa otp for digital services is out of scope for vrl.lta.gov.sgOTHEROut of Scope18:33
Addedtesting of the payment portal is out of scope for vrl.lta.gov.sgOTHEROut of Scope18:33
Addedesa functions not in-scope (using netrust token) for vrl.lta.gov.sgOTHEROut of Scope18:33
Addedhttps://www.vcc.bizfile.gov.sg/OTHEROut of Scope18:33
Addedhttps://smsgw.saasconnect.com/obh/SendSMSLegacyBCOTHEROut of Scope18:33
Addedhttps://prs.moh.gov.sg/OTHEROut of Scope18:33
Addedhttps://elis.moh.gov.sg/OTHEROut of Scope18:33
Addedhttps://sso-c.moh.gov.sg/esso/oidc/authorizeOTHEROut of Scope18:33
Addedhttps://halp.moh.gov.sg/OTHEROut of Scope18:33
Addedhttps://portal.nehr.sg/reportsOTHEROut of Scope18:33
Addedhttps://auth.nehr.sg/OTHEROut of Scope18:33
Addedhttps://c.go-mpulse.net/OTHEROut of Scope18:33
Addedhttps://s.go-mpulse.net/OTHEROut of Scope18:33
Addedhttps://www.tradenet.gov.sg/tradenet/portal/resetrequestOTHEROut of Scope18:33
Addedmessage hub module from https://www.tradenet.gov.sgOTHEROut of Scope18:33
Addedhttps://www2.cpf.gov.sg/OTHEROut of Scope18:33
Addedhttps://www.cpf.gov.sg/cayeOTHEROut of Scope18:33
Addedhttps://housing.cpf.gov.sg/OTHEROut of Scope18:33
Addedhttps://www.govpayouts.gov.sgOTHEROut of Scope18:33
Addedhttps://www.asean-ssa.org/OTHEROut of Scope18:33
Addedhttps://www.youtube.com/OTHEROut of Scope18:33
Addedhttps://www.google-analytics.com/OTHEROut of Scope18:33
Added*.wogaa.sgOTHEROut of Scope18:33
Addeduploading of the training record into the system, as the data will be used by other dependency system on service2.mom.gov.sgOTHEROut of Scope18:33
Addedhttps://www.customs.gov.sg/OTHEROut of Scope18:33