Subdomains under *.github.net run services for our internal production network. Many of these services are not accessible from outside our internal network.
*.github.net services.*.github.net.ssrf-target.iad.github.net to test out SSRF attacks.Some public DNS records resolve to RFC 1918 or otherwise internal addresses. On its own this tells an attacker nothing they can act on, because they still cannot route to those hosts. These reports are ineligible unless you pair them with a working path to reach the address, such as a server side request forgery that we can reproduce.
Not all subdomains are in-scope for rewards at this time and are therefore ineligible for rewards. A list of out-of-scope subdomains is available in our scope section.