Attack and Defense

142 posts

Attack and Defense banner
Attack and Defense

Attack and Defense

@attackndefense

@[email protected] - Mozilla's Security Internals for Security Engineers, Security Researchers, and Bug Bounty Hunters.

Tham gia Şubat 2020
8 Đang theo dõi1K Người theo dõi
Tweet ghim
Attack and Defense
Attack and Defense@attackndefense·
Please report bugs. If you - or someone else - improves exploitability after initial report, the bounty will be increased. If you're second reporter, you will be pro-rated. I guess I can only speak for our bounty program but come on industry, you can do better. #bugbountytips
Mustafa Can İPEKÇİ@mcipekci

Do not report open redirects without fully analyzing and seeing potentials of it. Thanks to random guy who reported open redirect, our report for full SSRF leaking client secret of integration claimed dupe. Again: do not report open redirects #bugbountytips

English
3
0
9
0
Attack and Defense đã retweet
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
After a long pause, a new video coming today! Part 1 of small documentary about Pwn2Own…
LiveOverflow 🔴 tweet media
English
12
41
515
24.3K
Attack and Defense
Attack and Defense@attackndefense·
(This is not the Firefox Security team, so we won't be able to answer a lot of the typical questions here)
English
0
0
0
190
Attack and Defense
Attack and Defense@attackndefense·
@MonierFr @garethheyes Doesn't DOMPurify also support <svg>? We intentionally disallow the more dangerous stuff (like <filter>, <view>, <switch>, etc.). But let us know if you find breakage. Attacks on web security APIs are generally in scope for the bug bounty program (terms and conditions apply :))
English
1
0
1
22
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here: portswigger-labs.net/mxss/ Set HTMLSanitizer ✅ Auto update ✅ I'm trying to break it, I encourage you to break it too
English
4
12
101
13.5K
Attack and Defense
Attack and Defense@attackndefense·
We just published the Q2 2025 edition of the Firefox Security and Privacy newsletter. Highlights: * CHIPS * Webcompat improvements * Better HTTPS error pages * Firefox Relay integration ...and much more. attackanddefense.dev/2025/07/17/fir…
English
0
1
1
189
Attack and Defense đã retweet
Masato Kinugawa
Masato Kinugawa@kinugawamasato·
bugzilla.mozilla.org/show_bug.cgi?i… This is a big change for DOM Clobberers. Firefox Nightly no longer allows native document properties to be overwritten by elements with a name attr, e.g.: <img src=a name=currentScript> <script> alert(document.currentScript)// HTMLScriptElement </script>
English
3
21
158
14.2K
Attack and Defense đã retweet
Firefox 🔥
Firefox 🔥@firefox·
We're turning the big 2-0 this year! Help us celebrate by sharing your best Firefox fan art 🔥 tag us or use #FirefoxArt by 11/01 so we don't miss it. (you just might score some fun surprises too...)
English
14
30
298
20.3K
Attack and Defense
Attack and Defense@attackndefense·
If you haven't updated Firefox in a while, do it now. We have fixed a high-severity security vulnerability that is apparently exploited in the wild. We shipped this within 25 hours after being reported to us. mozilla.org/en-US/security…
English
0
3
9
532
Attack and Defense
Attack and Defense@attackndefense·
Minor update to our our linked Security Severity Ratings and therefore the bug bounty program. We are decreasing the severity of 1. Memory safety issues that require just one _specific_ allocation to fail. 2. Full screen prompt spoofs.
English
1
1
2
519