Mozilla expands bug rewards for other web apps

Researchers can get a rewards for finding bugs for other Mozilla web properties

Mozilla has expanded the scope of its vulnerability reward program and will now pay out for problems found within applications used across its websites.

Researchers could earn between US$500 and $3,000 for finding a vulnerability in one of Mozilla's web properties, depending on the severity of the flaw. Mozilla wants researchers to track down coding errors such as cross-site scripting flaws and cross-site request forgery problems. Denial-of-service bugs won't be considered since those often do not involve a technical vulnerability within a web application, Mozilla said.

"We want to encourage the discovery of security issues within our web applications with the goal of keeping our users safe," Mozilla said on its security blog. "We also want to reward security researchers for their efforts with the hope of furthering constructive security research."

Researchers should not use automated tools on the sites to find the problems, Mozilla said, as that could affect its ability to keep the sites running properly. Instead, it encouraged researchers to download the open source code for its web applications to examine the code for problems and attack the software on their own servers.

In July, Mozilla upped the reward for finding bugs in its client applications from $500 to a maximum of $3,000. The organization said it felt the need to increase the maximum bounty to ensure it was economically sustainable for people to do the research.

At the time, the program applied only to the Firefox browser, Thunderbird e-mail client, the Firefox mobile browser and other services the products rely on. Mozilla published a list of its websites that now qualify for the program, but said others will be considered, depending on the flaw. Those that definitely qualify are:

* bugzilla.mozilla.org

*.services.mozilla.com

* getpersonas.com

* aus*.mozilla.org

* www.mozilla.com/org

* www.firefox.com

* www.getfirefox.com

* addons.mozilla.org

* services.addons.mozilla.org

* versioncheck.addons.mozilla.org

* pfs.mozilla.org

* download.mozilla.org

Join the PC World newsletter!

Error: Please check your email address.

Tags securitybugsMozilla Foundationdata protection

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service

Most Popular Reviews

Follow Us

Best Deals on GoodGearGuide

Shopping.com

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Latest Jobs

Shopping.com

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?