{"id":91827,"date":"2020-08-19T13:41:59","date_gmt":"2020-08-19T11:41:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej"},"modified":"2020-08-19T13:41:59","modified_gmt":"2020-08-19T11:41:59","slug":"mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej","title":{"rendered":"Mozilla ampl\u00eda su programa de recompensas por la detecci\u00f3n de vulnerabilidades","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>La compa\u00f1\u00eda Mozilla <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.mozilla.org\/attack-and-defense\/2020\/08\/18\/exploit-mitigation-bounty\/\">anunci\u00f3<\/a><\/noindex> sobre la expansi\u00f3n de la iniciativa de recompensas en efectivo por identificar problemas de seguridad en Firefox. Adem\u00e1s de las vulnerabilidades en s\u00ed, el programa Bug Bounty ahora incluir\u00e1 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mozilla.org\/en-US\/security\/client-bug-bounty\/#exploit-mitigation-bounty\">m\u00e9todos<\/a><\/noindex> la elusi\u00f3n de los mecanismos existentes en el navegador que impiden el funcionamiento de exploits. <\/p>\n<p>Entre los mecanismos de este tipo se incluye un sistema de limpieza de fragmentos HTML antes de su uso en un contexto privilegiado, la separaci\u00f3n de memoria para nodos DOM y strings\/ArrayBuffers, la prohibici\u00f3n de eval() en el contexto del sistema y en el proceso principal, la aplicaci\u00f3n de restricciones estrictas CSP (Content Security Policy) a las p\u00e1ginas auxiliares &#171;about:&#187;, la prohibici\u00f3n de cargar en el proceso principal p\u00e1ginas diferentes a &#171;chrome:\/\/&#187;, &#171;resource:\/\/&#187; y &#171;about:&#187;, la prohibici\u00f3n de ejecutar c\u00f3digo JavaScript externo en el proceso principal, y la elusi\u00f3n de los mecanismos de separaci\u00f3n de c\u00f3digo JavaScript privilegiado (usado para construir la interfaz del navegador) y de c\u00f3digo no privilegiado. Como ejemplo de un error que califica para el pago de una nueva recompensa, se menciona <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1583949\">la falta de<\/a><\/noindex> la verificaci\u00f3n de eval() en hilos de Web Workers.<\/p>\n<p>Al identificar una vulnerabilidad y eludir los mecanismos de protecci\u00f3n contra exploits, el investigador podr\u00e1 obtener un 50% adicional de la recompensa b\u00e1sica <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mozilla.org\/en-US\/security\/client-bug-bounty\/\">otorgada<\/a><\/noindex> por la vulnerabilidad identificada (por ejemplo, por una vulnerabilidad UXSS que elude el mecanismo  <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.mozilla.org\/attack-and-defense\/2019\/12\/02\/help-test-firefoxs-built-in-html-sanitizer-to-protect-against-uxss-bugs\/\">HTML Sanitizer<\/a><\/noindex>, se podr\u00e1 obtener $7000 m\u00e1s un bono de $3500). Cabe destacar que la expansi\u00f3n del programa de recompensas para investigadores independientes se lleva a cabo en el contexto del reciente <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53533\">despido<\/a><\/noindex> de 250 empleados de Mozilla, bajo el cual <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/MichalPurzynski\/status\/1293220570885062657\">la cuenta<\/a><\/noindex> todo el equipo de gesti\u00f3n de amenazas (Threat management team), que se ocupaba de identificar y analizar incidentes, as\u00ed como <noindex><a rel=\"nofollow\" href=\"https:\/\/news.ycombinator.com\/item?id=24121133\">parte del equipo<\/a><\/noindex>  Security team.<\/p>\n<p>Adem\u00e1s, se informa de un cambio en las reglas de aplicaci\u00f3n del programa de recompensas para vulnerabilidades identificadas en las versiones nocturnas. Se se\u00f1ala que tales vulnerabilidades a menudo se descubren inmediatamente durante las auditor\u00edas automatizadas internas y el fuzzing testing. Los informes de tales errores no conducen a mejoras en la seguridad de Firefox ni a la mejora de los mecanismos de fuzzing testing, por lo que las recompensas por vulnerabilidades en versiones nocturnas solo se otorgar\u00e1n si el problema ha estado presente en el repositorio principal durante m\u00e1s de 4 d\u00edas y ha pasado desapercibido en las auditor\u00edas internas y por parte de los empleados de Mozilla.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53567\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Mozilla \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e \u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0438 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u044b \u043f\u043e \u0432\u044b\u043f\u043b\u0430\u0442\u0435 \u0434\u0435\u043d\u0435\u0436\u043d\u044b\u0445 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0439 \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u0432 Firefox. \u041f\u043e\u043c\u0438\u043c\u043e \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 Bug Bounty \u0442\u0435\u043f\u0435\u0440\u044c \u0431\u0443\u0434\u0435\u0442 \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0442\u044c \u0438 \u043c\u0435\u0442\u043e\u0434\u044b \u043e\u0431\u0445\u043e\u0434\u0430 \u0438\u043c\u0435\u044e\u0449\u0438\u0445\u0441\u044f \u0432 \u0431\u0440\u0430\u0443\u0437\u0435\u0440\u0435 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432, \u043f\u0440\u0435\u043f\u044f\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0440\u0430\u0431\u043e\u0442\u0435 \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u043e\u0432. \u0412 \u0447\u0438\u0441\u043b\u043e \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u0445 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0432\u0445\u043e\u0434\u0438\u0442 \u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u0447\u0438\u0441\u0442\u043a\u0438 \u0444\u0440\u0430\u0433\u043c\u0435\u043d\u0442\u043e\u0432 HTML \u043f\u0435\u0440\u0435\u0434 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0432 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435, \u0440\u0430\u0437\u0434\u0435\u043b\u0435\u043d\u0438\u0435 \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u043b\u044f \u0443\u0437\u043b\u043e\u0432 DOM [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-91827","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Mozilla \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e \u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0438 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u044b \u043f\u043e \u0432\u044b\u043f\u043b\u0430\u0442\u0435 \u0434\u0435\u043d\u0435\u0436\u043d\u044b\u0445 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Mozilla \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u043b\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443 \u0432\u044b\u043f\u043b\u0430\u0442\u044b \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0439 \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Mozilla \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e \u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0438 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u044b \u043f\u043e \u0432\u044b\u043f\u043b\u0430\u0442\u0435 \u0434\u0435\u043d\u0435\u0436\u043d\u044b\u0445 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-19T11:41:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-19T11:41:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Mozilla ha ampliado el programa de recompensas por detecci\u00f3n de vulnerabilidades | ProHoster","description":"La compa\u00f1\u00eda Mozilla ha anunciado la expansi\u00f3n de su iniciativa de recompensas monetarias.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Mozilla \u0440\u0430\u0441\u0448\u0438\u0440\u0438\u043b\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0443 \u0432\u044b\u043f\u043b\u0430\u0442\u044b \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0439 \u0437\u0430 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Mozilla \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e \u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u0438\u0438 \u0438\u043d\u0438\u0446\u0438\u0430\u0442\u0438\u0432\u044b \u043f\u043e \u0432\u044b\u043f\u043b\u0430\u0442\u0435 \u0434\u0435\u043d\u0435\u0436\u043d\u044b\u0445 \u0432\u043e\u0437\u043d\u0430\u0433\u0440\u0430\u0436\u0434\u0435\u043d\u0438\u0439.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/mozilla-rasshirila-programmu-vyplaty-voznagrazhdenij-za-vyyavlenie-uyazvimostej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-19T11:41:59+00:00","article:modified_time":"2020-08-19T11:41:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"91827","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:20:24","updated":"2022-10-08 11:15:02","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/91827","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=91827"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/91827\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=91827"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=91827"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=91827"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}