Closed
Bug 1271438
Opened 10 years ago
Closed 10 years ago
Information disclosure in download.cdn.mozilla.net
Categories
(Websites :: Other, defect)
Websites
Other
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: adel.afsharipour, Assigned: jeff)
References
()
Details
(Keywords: reporter-external, sec-moderate, wsec-disclosure, Whiteboard: [reporter-external] [web-bounty-form] [verif?])
Hi,
So I was reading the Mozilla bug bounty page, where I saw that download.mozilla.org is part of scope. After trying to download Firefox browser, from that domain, I was eventually redirected to http://download.cdn.mozilla.net/pub/ where I found this below archive:
http://download.cdn.mozilla.net/pub/data/reporter.mozilla.org/reporter_mozilla_org_anonymized.sql.gz
The file is an old archive and also says it's been anonymized, however, after downloading it and importing it in my local MySql, I run a couple of queries in it, like SELECT * FROM `1_5_reports` WHERE `report_url` LIKE '%password=%' which basically results to some hosts where user credentials have been posted via GET, thus logged in the URL. Rest can be guessed easily :-)
It is true that the data is old and many of those websites even do not exist today, however, some of them contain VALID credentials!
So a general suggestion here is if such information is supposed to be shared with public, either make sure credentials are removed from it, or some how consider a disclaimer policy that Mozilla is not responsible after some years ...
Thanks for reading my report!
Regards,
Adel
Flags: sec-bounty?
Comment 1•10 years ago
|
||
Data deleted, thanks for the report.
| Assignee | ||
Updated•10 years ago
|
Assignee: nobody → mkelly
Comment 2•10 years ago
|
||
dolske: dao: After some digging, it looks like reporter.mozilla.org was the service behind the old "Broken Website" reporter thing that used to be in Firefox. I found your names on bug 430217; can you confirm what reporter.mozilla.org was, and possibly why we have these dumps up on download.mozilla.org?
Alternatively, pointers to whoever maintained the service are also welcome. :D
Flags: needinfo?(dolske)
Flags: needinfo?(dao+bmo)
Comment 3•10 years ago
|
||
oremj: Two questions:
1. Are we able to remove the cached version of the dump that the CDN is still currently serving? Will it eventually go away already?
2. Do we have any way of tracing what wrote that dump in the first place so we can see if there's a cronjob or something still making those dumps?
Flags: needinfo?(oremj)
Comment 4•10 years ago
|
||
(In reply to Michael Kelly [:mkelly,:Osmose] from comment #3)
> 1. Are we able to remove the cached version of the dump that the CDN is
> still currently serving? Will it eventually go away already?
Scratch that, ulfr just told me that you've already invalidated the cache. Thanks! :D
Updated•10 years ago
|
Assignee: mkelly → jbryner
Comment 5•10 years ago
|
||
Ulfr noted the file hasn't been updated since the netapp -> s3 migration, so that file has likely been there for a very long time.
Updated•10 years ago
|
Flags: needinfo?(oremj)
Comment 6•10 years ago
|
||
Yes, reporter.mozilla.org was the backend for the old "report a broken website" command in Firefox; we removed it in Firefox 4 back in bug 572695 / bug 590492. That was almost 6 years ago, and IIRC even at the time it was an under-maintained service not really being used or monitored. The bugs in Webtools :: Reporter and Other Applications :: Reporter are similarly crusty.
I'm not sure who actually worked on the Reporter backend, but robert@accettura.com is listed as the owner on a number of them, and that vaguely rings a bell. You might NI him. But afaik the site's been dead a long time, and so there's no reason for any of it to be around.
Ah-ha:
I see some commentary in bug 572026 that talks about doing a DB dump and making it available as a useful source of webcompat issues... Yeah, and there was a blog post that linked to it: https://blog.mozilla.org/website-archive/2010/12/08/mozilla-reporter/
Flags: needinfo?(dolske)
Updated•10 years ago
|
Flags: needinfo?(dao+bmo)
Comment 7•10 years ago
|
||
http://download.cdn.mozilla.net/pub/labs/mozillalabs.com-wpmu/
File labs_wpmu_2012-06-05.sql.gz 8M 09-Sep-2015 18:50
File mozillalabs.com_code_archive.tar 10M 09-Sep-2015 18:50
File mozillalabs.com_uploads_archive.tar 30M 09-Sep-2015 18:50
File mozillalabs.com_wp_wp-content.tar 10M 09-Sep-2015 18:50
Comment 8•10 years ago
|
||
http://download.cdn.mozilla.net/pub/data/markup.mozilla.org/
File markup_mark_anonymized.sql.bz2 2502M 27-Oct-2015 17:38
Comment 9•10 years ago
|
||
https://ftp.mozilla.org/pub/mozilla/VMs/
File CentOS5-ReferencePlatform.tar.bz2 3091M 27-Oct-2015 17:39 <-------
File b2g.box 10858M 02-Nov-2015 20:57
Should this be on the CDN?
Not sure what b2g.box is, but it's big
Comment 10•10 years ago
|
||
Comment 11•10 years ago
|
||
A subset is on stage
http://ftp.stage.mozaws.net/pub/labs/mozillalabs.com-wpmu/
Updated•10 years ago
|
Keywords: wsec-disclosure
Updated•10 years ago
|
Status: UNCONFIRMED → NEW
Ever confirmed: true
Comment 12•10 years ago
|
||
Old user surveys. Not sensitive but some f-bombs were dropped. Should remove.
Comment 13•10 years ago
|
||
Updated•10 years ago
|
Flags: needinfo?(jvehent)
Comment 14•10 years ago
|
||
Directories like
http://download.cdn.mozilla.net/pub/b2g/try-builds/
and others under different product dirs contain gb and gb of builds we don't need to be storing on the CDN.
The containing dirs are named try-builds as above
Comment 15•10 years ago
|
||
I provided a dump of the filenames in those S3 buckets to infosec. This bug can be closed and another bug will be opened if more files need to be removed.
Status: NEW → RESOLVED
Closed: 10 years ago
Flags: needinfo?(jvehent)
Resolution: --- → FIXED
| Reporter | ||
Comment 16•10 years ago
|
||
(In reply to Julien Vehent [:ulfr] from comment #15)
> I provided a dump of the filenames in those S3 buckets to infosec. This bug
> can be closed and another bug will be opened if more files need to be
> removed.
Hi Julien,
Thanks for your comment. Am I allowed to write a blog post about this issue?
Regards,
Adel
| Reporter | ||
Comment 17•10 years ago
|
||
Hi @all, I would like to know if this issue qualifies for any bounty/thanks under hall of fame/ and if I'm allowed to write blog post about this issue?
| Assignee | ||
Comment 18•10 years ago
|
||
@Adel; it does qualify for bounty consideration (notice the sec-bounty:? flag in the bug header).
The bounty committee meets weekly to discuss resolved bugs and if a bounty is granted it will be marked sec-bounty: +
We are a bit behind on bounty meetings due to a company work week and travel schedules, thanks for you patience.
As far as blog post, the bug is currently marked confidential. If/when this flag is removed then the issue is considered public and can therefore be discussed publicly.
| Reporter | ||
Comment 19•10 years ago
|
||
Thanks a lot for the update.
Best Regards,
Adel
Updated•10 years ago
|
Keywords: sec-moderate
Updated•10 years ago
|
Group: websites-security
Flags: sec-bounty? → sec-bounty+
Updated•2 years ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•