swiss-post

YesWeHackView on YesWeHack
RawAI Enhanced
11
In Scope
5
Out of Scope
In-Scope Assets (11)
Out-of-Scope Assets (5)
AssetCategoryBounty
Any services related to Incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHERYes
Anything that has not been described as in scope in the previous section is automatically out of scope.OTHERYes
Attacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes DNS, NTP, routers, systems of the ISP, etc.).OTHERYes
Please note that some of the applications may contain links or redirect you away from the URIs described in the scope section. This means you are leaving the scope if you follow these links / redirects.OTHERYes
The alternative login (https://login.swissid.ch) is out of scope. It also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scope.OTHERYes
Scope Changes (16)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Added(*.post.ch:80|*.post.ch:443) and 194.41.128.0/17OTHERIn Scope18:33
Addedhttps://account.post.chURLIn Scope18:33
Addedhttps://shop.post.ch/shopURLIn Scope18:33
Addedhttps://service.post.ch/ekp-webURLIn Scope18:33
Addedhttps://service.post.ch/zopa/appURLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=com.nth.swisspost&hl=de_CH&gl=USANDROIDIn Scope18:33
Addedhttps://apps.apple.com/ch/app/die-post/id378676700IOSIn Scope18:33
Addedhttps://itunes.apple.com/ch/app/postcard-creator/id820354055?mt=8IOSIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=ch.post.it.pcc&hl=enANDROIDIn Scope18:33
Addedhttps://billingonline.post.ch/OnlinePayment/Web/v1/BOIURLIn Scope18:33
Addedhttps://service.post.ch/ele-klp/eleURLIn Scope18:33
Addedanything that has not been described as in scope in the previous section is automatically out of scopeOTHEROut of Scope18:33
Addedattacks on administrative and surrounding systems that are not used for the in-scope services are not permitted (this includes dns, ntp, routers, systems of the isp, etc.)OTHEROut of Scope18:33
Addedthe alternative login (https://login.swissid.ch) is out of scope. it also leads to the in-scope service, (https://account.post.ch) but we have designated it as out of scopeOTHEROut of Scope18:33
Addedany services related to incamail (for example https://incamail-dev.post.ch (194.41.248.224) and https://incamail-test.post.ch (194.41.248.58))OTHEROut of Scope18:33
Addedplease note that some of the applications may contain links or redirect you away from the uris described in the scope section. this means you are leaving the scope if you follow these links / redirectsOTHEROut of Scope18:33