{"id":149,"date":"2011-10-04T03:00:57","date_gmt":"2011-10-04T11:00:57","guid":{"rendered":"http:\/\/blog.mozilla.org\/webappsec\/?p=149"},"modified":"2011-10-04T03:00:57","modified_gmt":"2011-10-04T11:00:57","slug":"mozilla-bug-bounty-update","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/","title":{"rendered":"Mozilla Bug Bounty Update"},"content":{"rendered":"<p>We&#8217;re nearly three quarters the way through 2011 and we wanted to provide an update on the progress of the Mozilla bug bounty programs.\u00a0 The goal of the Mozilla bounty programs is to encourage security research in Mozilla software, reward the individuals that are participating in this research, and continue pursuing the safest browsing and web experience for all users.<\/p>\n<p>The Firefox bug bounty was created in 2004 and has demonstrated its success over the past 7+ years. At the end of 2010, the bounty program was expanded and select high value Mozilla web sites were also included into a Mozilla web bounty program. Statistics on the success of the web bounty program were recently presented at the <a href=\"http:\/\/www.appsecusa.org\/schedule.html\">OWASP AppSecUSA<\/a> conference and the slides, along with statistics, are available <a href=\"http:\/\/www.slideshare.net\/michael_coates\/bug-bounty-programs-for-the-web\">here<\/a>.<\/p>\n<p>Between the two bounty programs Mozilla has paid over $200,000 in bounties during 2011 for previously unknown security bugs in Firefox or our critical Mozilla web applications.\u00a0 These programs have established a productive dialog between the Mozilla community and numerous security researchers. In addition, each bounty bug report has enabled Mozilla to further refine the security controls in our products and web applications to deliver a more secure browsing and web experience to hundreds of millions of users around the world.<\/p>\n<p>If you are interested in getting involved in the Mozilla bug bounty program then please check out the following links:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.mozilla.org\/security\/bug-bounty.html\">Mozilla bug bounty program overview<\/a><\/li>\n<li><a href=\"http:\/\/www.mozilla.org\/security\/bug-bounty-faq.html\">Details and FAQ for Firefox bounty program<\/a><\/li>\n<li><a href=\"http:\/\/www.mozilla.org\/security\/bug-bounty-faq-webapp.html\">Details and FAQ for Mozilla websites bounty program<\/a><\/li>\n<\/ul>\n<p>&#8211; <a href=\"http:\/\/people.mozilla.org\/~mcoates\/\">Michael Coates<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;re nearly three quarters the way through 2011 and we wanted to provide an update on the progress of the Mozilla bug bounty programs.\u00a0 The goal of the Mozilla bounty &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/\">Read more<\/a><\/p>\n","protected":false},"author":1438,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[121],"tags":[],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mozilla Bug Bounty Update - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"mozilla\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/\",\"name\":\"Mozilla Bug Bounty Update - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2011-10-04T11:00:57+00:00\",\"dateModified\":\"2011-10-04T11:00:57+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mozilla Bug Bounty Update\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9\",\"name\":\"mozilla\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/98138a294cb6e19a68b02ef8ca9be2dc\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g\",\"caption\":\"mozilla\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mozilla Bug Bounty Update - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/","twitter_misc":{"Written by":"mozilla","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/","url":"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/","name":"Mozilla Bug Bounty Update - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2011-10-04T11:00:57+00:00","dateModified":"2011-10-04T11:00:57+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2011\/10\/04\/mozilla-bug-bounty-update\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Mozilla Bug Bounty Update"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/70ae25c16f09d053c6d8b5eac29dbda9","name":"mozilla","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/98138a294cb6e19a68b02ef8ca9be2dc","url":"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/75d2017e019c87560fe5d148a64659dc?s=96&d=identicon&r=g","caption":"mozilla"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/149"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/1438"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=149"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/149\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=149"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=149"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=149"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}