Mozilla
Menu
  • About Mozilla
  • Products
  • Give
  • Discover Firefox

Attack & Defense (Archive)

This blog has moved to https://attackanddefense.dev/

  • Explore

Help Test Firefox’s built-in HTML Sanitizer to protect against UXSS bugs

Frederik Braun
December 2, 2019

This post first appeared on the Mozilla Security Blog I recently gave a talk at OWASP Global AppSec in Amsterdam and summarized the presentation in a blog post about how … Read more

Adding CodeQL and clang to our Bug Bounty Program

Tom Ritter
November 14, 2019

This post first appeared on the Mozilla Security Blog. At Github Universe, Github announced the GitHub Security Lab, an initiative to help secure open source software alongside the community and … Read more

Remote Code Execution in Firefox beyond memory corruptions

Frederik Braun
September 29, 2019

This is the blog post version of my presentation form OWASP Global AppSec in Amsterdam 2019. It was presented in the AllStars Track. Abstract: Browsers are complicated enough to have … Read more

  • Previous
  • Page1
  • Page2
  • Page3

About Attack & Defense

The Attack & Defense blog is targeted directly at security researchers who are interested in new developments in Mozilla’s Bug Bounty, and guides, tips, and tricks for finding bugs in Firefox.

Recent Posts

  • IPC Fuzzing with Snapshots June 24, 2024
  • WebAssembly and Back Again: Fine-Grained Sandboxing in Firefox 95 December 6, 2021
  • Finding and Fixing DOM-based XSS with Static Analysis November 3, 2021
  • Implementing form filling and accessibility in the Firefox PDF viewer October 14, 2021
  • Fixing a Security Bug by Changing a Function Signature September 29, 2021

Stay in touch

  • Follow us on Twitter
  • Subscribe to our RSS Feed

Keep up with
all things Firefox.

We will only send you Mozilla-related information.

Thanks!

If you haven’t previously confirmed a subscription to a Mozilla-related newsletter you may have to do so. Please check your inbox or your spam filter for an e-mail from us.

Mozilla
Mozilla
  • About
  • Contact Us
  • Donate
    • Twitter (@mozilla)
    • Instagram (@mozillagram)
Firefox
  • Download Firefox
  • Desktop
  • Mobile
  • Features
  • Beta, Nightly, Developer Edition
    • Twitter (@firefox)
    • YouTube (firefoxchannel)
  • Website Privacy Notice
  • Cookies
  • Legal

Visit Mozilla Corporation’s not-for-profit parent, the Mozilla Foundation.

Portions of this content are ©1998-2026 by individual contributors. Content available under a Creative Commons license.