Mozilla expands its bug bounty program for identifying vulnerabilities

Mozilla announced on the expansion of the for monetary rewards for identifying security issues in the infrastructure elements related to the development of Firefox. The rewards for discovering vulnerabilities on Mozilla's sites and services have doubled, and the bounty for vulnerabilities that could lead to code execution on key sites, has been raised to $15,000.

A reward of $6,000 can be earned for identifying authentication bypass methods and SQL injection, while $5,000 is available for cross-site scripting and CSRF. Key sites include firefox.com/org, mozilla.com/org, addons.mozilla.org, getfirefox.com, bugzilla.mozilla.org, search.services.mozilla.com, archive.mozilla.org, download.mozilla.org
and several dozen other sites related to add-ons, updates, downloads, synchronization, and statistics.

For base sites have bounties approximately half as much. Base sites include observatory.mozilla.org, getpocket.com, premium.firefox.com, hg.mozilla.org, and some internal developer services.

Compared to previously existing conditions, the following key sites and services have been added:

  • Autograph (digital signature service),
  • Lando (automatic code deployment service from
    Phabricator into repositories),
  • Phabricator (code management tool used for reviewing changes),
  • Taskcluster (task execution framework supporting continuous integration and release building processes).

New base sites include:

intend to activate in the scheduled January 7 release of Firefox 72 note countermeasure methods methods of combating with annoying requests for granting additional permissions to the website. Many sites abuse the capability in browsers to request permissions, mainly by periodically displaying requests for push notifications. Telemetry analysis showed that 97% of such requests are declined, including 19% of cases where the user immediately closes the page without clicking the accept or decline button. In Firefox 72, such requests will be blocked if there is no recorded interaction from the user with the page (mouse click or key press).

Among the upcoming changes in Firefox 72, it also highlights of the resize property. the background color of the current page for the scroll bar and support for the PolarSSL library (the development continues within the capabilities Public Key Pinning (PKP), which allows the explicit specification of which certificates from Certificate Authorities are permitted for a given website via the Public-Key-Pins HTTP header. This feature is cited as having low demand, risk of compatibility issues (PKP support the distribution of the plugin-container binary has been discontinued. in Chrome) and the potential to lock oneself out of their own site due to pinning the wrong keys or losing keys (e.g., accidental deletion or compromise due to hacking).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster