{"id":442,"date":"2011-01-27T18:13:08","date_gmt":"2011-01-28T01:13:08","guid":{"rendered":"http:\/\/blog.mozilla.org\/security\/?p=442"},"modified":"2011-01-27T18:14:22","modified_gmt":"2011-01-28T01:14:22","slug":"web-bounty-update","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/","title":{"rendered":"Web Bounty Update"},"content":{"rendered":"<p>It has been just over a month since we announced the expansion of our  bounty program to include selected web applications.\u00a0 We have received  many bug reports and have awarded $40,000. We will make the resolved  bugs public shortly as these issues are no longer a threat to the  community and our users.<\/p>\n<p>Since the announcement of the web bounty program, we have received many  security bug reports for sites outside of the bounty. We want to <strong>reiterate the eligible sites and applications for the bounty<\/strong>.<\/p>\n<ul>\n<li> addons.mozilla.org<\/li>\n<li> aus*.mozilla.org<\/li>\n<li> bugzilla.mozilla.org<\/li>\n<li> download.mozilla.org<\/li>\n<li> getpersonas.com<\/li>\n<li> pfs.mozilla.org<\/li>\n<li> services.addons.mozilla.org<\/li>\n<li> versioncheck.addons.mozilla.org<\/li>\n<li> www.mozilla.com\/org<\/li>\n<li> www.firefox.com<\/li>\n<li> www.getfirefox.com<\/li>\n<li> *.services.mozilla.com<\/li>\n<\/ul>\n<p>We want to focus our attention on security issues that protect Firefox  users.\u00a0 We excluded other sites for various reasons, including: we plan  on replacing them, or we have put these systems in a read only state to  lessen their impact. Further details can be found on the <a href=\"http:\/\/www.mozilla.org\/security\/bug-bounty-faq-webapp.html\">Web Security  Bounty FAQ,<\/a> which should be reviewed before submitting a web bounty bug.<\/p>\n<p>Thanks to all the bug submitters for their contributions; the program  has been a great success.\u00a0 Beyond the monetary rewards, we sent Mozilla  T-shirts to an additional 23 people who submitted security bugs that did  not qualify for the web bug bounty. We are in the process of triage for  the next round of payments and more should be going out soon.<\/p>\n<p>Chris Lyon<br \/>\nDirector of Infrastructure Security<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It has been just over a month since we announced the expansion of our bounty program to include selected web applications.\u00a0 We have received many bug reports and have awarded &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/\">Read more<\/a><\/p>\n","protected":false},"author":175,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69],"tags":[4459,335],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Web Bounty Update  - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Chris Lyon\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/\",\"name\":\"Web Bounty Update - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2011-01-28T01:13:08+00:00\",\"dateModified\":\"2011-01-28T01:14:22+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/ea919a02109b25695672251a83c2120e\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Web Bounty Update\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/ea919a02109b25695672251a83c2120e\",\"name\":\"Chris Lyon\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/feee60d163cdfc62fe2d9c5d49cae0ec\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/279c764abcbdce6373555f5fbc43f327?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/279c764abcbdce6373555f5fbc43f327?s=96&d=identicon&r=g\",\"caption\":\"Chris Lyon\"},\"description\":\"Director of Infrastructure Security\",\"sameAs\":[\"http:\/\/cslyon.net\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Web Bounty Update  - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/","twitter_misc":{"Written by":"Chris Lyon","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/","url":"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/","name":"Web Bounty Update - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2011-01-28T01:13:08+00:00","dateModified":"2011-01-28T01:14:22+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/ea919a02109b25695672251a83c2120e"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2011\/01\/27\/web-bounty-update\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Web Bounty Update"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/ea919a02109b25695672251a83c2120e","name":"Chris Lyon","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/feee60d163cdfc62fe2d9c5d49cae0ec","url":"https:\/\/secure.gravatar.com\/avatar\/279c764abcbdce6373555f5fbc43f327?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/279c764abcbdce6373555f5fbc43f327?s=96&d=identicon&r=g","caption":"Chris Lyon"},"description":"Director of Infrastructure Security","sameAs":["http:\/\/cslyon.net"]}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/442"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/175"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=442"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/442\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=442"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=442"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=442"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}