— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Mozilla.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
first indexed
56d ago · 24 in-scope assets
// only one snapshot on record — changes appear from the next ingest onward
{
"id": 0,
"url": "https://hackerone.com/mozilla",
"name": "Mozilla",
"handle": "mozilla",
"targets": {
"in_scope": [
{
"asset_type": "OTHER",
"instruction": "Collection of APIs which power placing recommended stories on new Firefox tabs.\n\nIt uses the below domains:\n- client-api.getpocket.com\n- admin-api.getpocket.com\n- curation-admin-tools.readitlater.com\n\nWhile testing, do not add or modify any data on production, instead, testing should be done on a local instance. Data is managed using the admin API and the curation admin tools. The client API serves the data in the browser.\n\nSource Code: https://github.com/Pocket/content-monorepo/",
"max_severity": "critical",
"asset_identifier": "Firefox Homepage Newtab",
"eligible_for_bounty": true,
"integrity_requirement": "high",
"eligible_for_submission": true,
"availability_requirement": "medium",
"confidentiality_requirement": "low"
},
{
"asset_type": "OTHER",
"instruction": "Mozilla Ad Routing Service (MARS) under the below domains:\n- ads.mozilla.org (mars.prod.ads.prod.webservices.mozgcp.net)\n- ads.allizom.org (mars.stage.ads.nonprod.webservices.mozgcp.net)\n- mars.qa.ads.nonprod.webservices.mozgcp.net\n- ads-img.mozilla.org\n- ads-img.allizom.org\n- contile.services.mozilla.com\n- spocs.getpocket.com\n- spocs.getpocket.dev\n- spocs.mozilla.net\n- spocs.allizom.net\n\nTesting to be done on the staging instance: \n- ads.allizom.org\n\nSource Code: https://github.com/mozilla-services/mars",
"max_severity": "critical",
"asset_identifier": "Mozilla Ad Routing Service",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "OTHER",
"instruction": "**Do not run automated scans on those domains**\n\nFirefox Downloads which include the below sites:\n- archive.mozilla.org\n- download.mozilla.org\n- download-installer.cdn.mozilla.net\n- treeherder.mozilla.org\n\nNote that content on these assets is intentionally public.\n\nSource Code: https://github.com/mozilla/treeherder",
"max_severity": "critical",
"asset_identifier": "Product Delivery",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Mozilla Accounts (previously known as Firefox Accounts)\n\nAdditional domains in scope for Firefox Accounts:\n* api.accounts.firefox.com\n* oauth.accounts.firefox.com\n* profile.accounts.firefox.com\n* verifier.accounts.firefox.com\n* graphql.accounts.firefox.com\n* subscriptions.firefox.com\n\nSource Code: https://github.com/mozilla/fxa",
"max_severity": "critical",
"asset_identifier": "accounts.firefox.com",
"eligible_for_bounty": true,
"integrity_requirement": "high",
"eligible_for_submission": true,
"availability_requirement": "high",
"confidentiality_requirement": "high"
},
{
"asset_type": "URL",
"instruction": "This is the staging server for Firefox Addons. Testing should be restricted to this instance without any testing on production.\n\nAdditional domains for Addons:\n - services.addons.allizom.org\n - versioncheck-bg.addons.allizom.org\n - versioncheck.addons.allizom.org\n\nSource Code: https://github.com/mozilla/addons-server",
"max_severity": "critical",
"asset_identifier": "addons.allizom.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Backend update system for Mozilla products.\n\nNo disruptive testing or scanning tools to be run on production.\n\nSource Code: https://github.com/mozilla-releng/balrog ",
"max_severity": "critical",
"asset_identifier": "aus5.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Mozilla owned Bugzilla instance.\n\nPlease do not use automated scanners, create, or modify bugs when testing Bugzilla. Instead, testing should be only done on the development instance, bugzilla-dev.allizom.org.\n\nSource Code: https://github.com/mozilla-bteam/bmo",
"max_severity": "critical",
"asset_identifier": "bugzilla.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Endpoint for sending Firefox crash reports.\n\nTesting to be done on staging instance: https://crash-reports.allizom.org/\n\nSource Code: https://github.com/mozilla-services/socorro",
"max_severity": "critical",
"asset_identifier": "crash-reports.allizom.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Analytics site for Firefox crash reports data.\n\nTesting to be done on staging instance only: https://crash-stats.allizom.org/\n\nSource Code: https://github.com/mozilla-services/socorro",
"max_severity": "critical",
"asset_identifier": "crash-stats.allizom.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Please use the staging instance for intrusive tests or for tests which change the content: https://developer.allizom.org\n\nSource Code: \nMain application: https://github.com/mdn/mdn\nRepos under https://github.com/mdn",
"max_severity": "critical",
"asset_identifier": "developer.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "TaskCluster CI/CD tool instance used for Firefox builds.\n\nSource Code: https://github.com/taskcluster/taskcluster",
"max_severity": "critical",
"asset_identifier": "firefox-ci-tc.services.mozilla.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Service which manages configuration in Firefox.\n\nAdditional domains for Remote Settings:\n- firefox-settings-attachments.cdn.mozilla.net\n\nTesting to be performed on staging instance only: https://firefox.settings.services.allizom.org/v1/",
"max_severity": "critical",
"asset_identifier": "firefox.settings.services.mozilla.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "The website used for source code and version control hosting for Firefox.\n\nWeb vulnerabilities that affect the website itself and not the source code will be considered as vulnerabilities in a **Core Site**.\n\nVulnerabilities that affect the source code itself will be considered as vulnerabilities in a **Critical Site**.\n\nSource Code: https://github.com/mozilla/version-control-tools\n",
"max_severity": "critical",
"asset_identifier": "hg.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Tool used to land Firefox code into Mercurial.\n\nAdditional Domains: \n- api.lando.services.mozilla.com\n- lando.moz.tools\n\nTesting to be done on staging or development instances only:\n- ui.dev.lando.nonprod.cloudops.mozgcp.net\n- ui.stage.lando.nonprod.cloudops.mozgcp.net\n- api.dev.lando.nonprod.cloudops.mozgcp.net\n- api.stage.lando.nonprod.cloudops.mozgcp.net\n\nSource Code: \n- https://github.com/mozilla-conduit/lando\n- https://github.com/mozilla-conduit/lando-api \n- https://github.com/mozilla-conduit/lando-ui",
"max_severity": "critical",
"asset_identifier": "lando.services.mozilla.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Firefox Suggest\n\nTesting to be performed on the staging instance only: https://merino.services.allizom.org\n\nSource Code: https://github.com/mozilla-services/merino-py",
"max_severity": "critical",
"asset_identifier": "merino.services.mozilla.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Mozilla Monitor\n\nSource Code: https://github.com/mozilla/blurts-server",
"max_severity": "critical",
"asset_identifier": "monitor.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Testing to be done **only** on the development instance (phabricator-dev.allizom.org) or the staging instance (phabricator.allizom.org)\n\nSource Code: https://github.com/mozilla-conduit/phabricator",
"max_severity": "critical",
"asset_identifier": "phabricator.allizom.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Staging instance for Mozilla Localization Service.\n\nTesting is to be done on this instance only, testing on production is not acceptable.\n\nSource Code: https://github.com/mozilla/pontoon",
"max_severity": "critical",
"asset_identifier": "pontoon.allizom.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Testing to be done on the staging instance only: https://relay.allizom.org/\n\nPlease set the HTTP header \"X-HackerOne-Research\" when sending requests to the Relay servers, so that the traffic can be identified as resulting from bug bounty testing.\n\nThe team would like testing to be focused on the APIs listed here: https://mozilla.github.io/fx-private-relay/api_docs.html\n\nSource Code: https://github.com/mozilla/fx-private-relay",
"max_severity": "critical",
"asset_identifier": "relay.firefox.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Support platform for all of Mozilla Products.\n\n**Testing to be done on staging instance only to avoid disrupting users: support.allizom.org**\n\nSource Code: https://github.com/mozilla/kitsune",
"max_severity": "critical",
"asset_identifier": "support.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Firefox Sync Domains:\n- *.sync.services.mozilla.com\n- token.services.mozilla.com\n\nSource Code: \n- https://github.com/mozilla-services/syncstorage-rs\n- https://github.com/mozilla-services/tokenlib/",
"max_severity": "critical",
"asset_identifier": "sync.services.mozilla.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "The backend server behind Mozilla VPN.\n",
"max_severity": "critical",
"asset_identifier": "vpn.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Firefox Marketing Website aka Springfield. Only the website is included in the scope, not the Firefox client.\n\n Please use our staging instance, www.springfield.moz.works, for testing to avoid site disruption.\n\nSource Code: https://github.com/mozmeao/springfield",
"max_severity": "critical",
"asset_identifier": "www.firefox.com",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
},
{
"asset_type": "URL",
"instruction": "Mozilla Marketing Website aka Bedrock.\n\n Please use our staging instance, www.allizom.org, for testing to avoid site disruption.\n\nSource Code: https://github.com/mozilla/bedrock",
"max_severity": "critical",
"asset_identifier": "www.mozilla.org",
"eligible_for_bounty": true,
"integrity_requirement": null,
"eligible_for_submission": true,
"availability_requirement": null,
"confidentiality_requirement": null
}
],
"out_of_scope": []
},
"website": "https://www.mozilla.org",
"offers_swag": false,
"managed_program": true,
"offers_bounties": true,
"submission_state": "open",
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 365,
"response_efficiency_percentage": 80,
"average_time_to_report_resolved": 968,
"average_time_to_first_program_response": 1
}aus5.mozilla.org· criticallando.services.mozilla.com· criticalmerino.services.mozilla.com· criticalmonitor.mozilla.org· criticalphabricator.allizom.org· criticalpontoon.allizom.org· criticalrelay.firefox.com· criticalsupport.mozilla.org· criticalsync.services.mozilla.com· criticalvpn.mozilla.org· criticalwww.firefox.com· criticalwww.mozilla.org· criticalFirefox Homepage Newtab· criticalMozilla Ad Routing Service· criticalProduct Delivery· critical— none listed —