Closed Bug 1271438 Opened 10 years ago Closed 10 years ago

Information disclosure in download.cdn.mozilla.net

Categories

(Websites :: Other, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: adel.afsharipour, Assigned: jeff)

References

()

Details

(Keywords: reporter-external, sec-moderate, wsec-disclosure, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Hi, So I was reading the Mozilla bug bounty page, where I saw that download.mozilla.org is part of scope. After trying to download Firefox browser, from that domain, I was eventually redirected to http://download.cdn.mozilla.net/pub/ where I found this below archive: http://download.cdn.mozilla.net/pub/data/reporter.mozilla.org/reporter_mozilla_org_anonymized.sql.gz The file is an old archive and also says it's been anonymized, however, after downloading it and importing it in my local MySql, I run a couple of queries in it, like SELECT * FROM `1_5_reports` WHERE `report_url` LIKE '%password=%' which basically results to some hosts where user credentials have been posted via GET, thus logged in the URL. Rest can be guessed easily :-) It is true that the data is old and many of those websites even do not exist today, however, some of them contain VALID credentials! So a general suggestion here is if such information is supposed to be shared with public, either make sure credentials are removed from it, or some how consider a disclaimer policy that Mozilla is not responsible after some years ... Thanks for reading my report! Regards, Adel
Flags: sec-bounty?
Data deleted, thanks for the report.
Assignee: nobody → mkelly
dolske: dao: After some digging, it looks like reporter.mozilla.org was the service behind the old "Broken Website" reporter thing that used to be in Firefox. I found your names on bug 430217; can you confirm what reporter.mozilla.org was, and possibly why we have these dumps up on download.mozilla.org? Alternatively, pointers to whoever maintained the service are also welcome. :D
Flags: needinfo?(dolske)
Flags: needinfo?(dao+bmo)
oremj: Two questions: 1. Are we able to remove the cached version of the dump that the CDN is still currently serving? Will it eventually go away already? 2. Do we have any way of tracing what wrote that dump in the first place so we can see if there's a cronjob or something still making those dumps?
Flags: needinfo?(oremj)
(In reply to Michael Kelly [:mkelly,:Osmose] from comment #3) > 1. Are we able to remove the cached version of the dump that the CDN is > still currently serving? Will it eventually go away already? Scratch that, ulfr just told me that you've already invalidated the cache. Thanks! :D
Assignee: mkelly → jbryner
Ulfr noted the file hasn't been updated since the netapp -> s3 migration, so that file has likely been there for a very long time.
Flags: needinfo?(oremj)
Yes, reporter.mozilla.org was the backend for the old "report a broken website" command in Firefox; we removed it in Firefox 4 back in bug 572695 / bug 590492. That was almost 6 years ago, and IIRC even at the time it was an under-maintained service not really being used or monitored. The bugs in Webtools :: Reporter and Other Applications :: Reporter are similarly crusty. I'm not sure who actually worked on the Reporter backend, but robert@accettura.com is listed as the owner on a number of them, and that vaguely rings a bell. You might NI him. But afaik the site's been dead a long time, and so there's no reason for any of it to be around. Ah-ha: I see some commentary in bug 572026 that talks about doing a DB dump and making it available as a useful source of webcompat issues... Yeah, and there was a blog post that linked to it: https://blog.mozilla.org/website-archive/2010/12/08/mozilla-reporter/
Flags: needinfo?(dolske)
Flags: needinfo?(dao+bmo)
http://download.cdn.mozilla.net/pub/labs/mozillalabs.com-wpmu/ File labs_wpmu_2012-06-05.sql.gz 8M 09-Sep-2015 18:50 File mozillalabs.com_code_archive.tar 10M 09-Sep-2015 18:50 File mozillalabs.com_uploads_archive.tar 30M 09-Sep-2015 18:50 File mozillalabs.com_wp_wp-content.tar 10M 09-Sep-2015 18:50
http://download.cdn.mozilla.net/pub/data/markup.mozilla.org/ File markup_mark_anonymized.sql.bz2 2502M 27-Oct-2015 17:38
https://ftp.mozilla.org/pub/mozilla/VMs/ File CentOS5-ReferencePlatform.tar.bz2 3091M 27-Oct-2015 17:39 <------- File b2g.box 10858M 02-Nov-2015 20:57 Should this be on the CDN? Not sure what b2g.box is, but it's big
Status: UNCONFIRMED → NEW
Ever confirmed: true
Old user surveys. Not sensitive but some f-bombs were dropped. Should remove.
Flags: needinfo?(jvehent)
Directories like http://download.cdn.mozilla.net/pub/b2g/try-builds/ and others under different product dirs contain gb and gb of builds we don't need to be storing on the CDN. The containing dirs are named try-builds as above
I provided a dump of the filenames in those S3 buckets to infosec. This bug can be closed and another bug will be opened if more files need to be removed.
Status: NEW → RESOLVED
Closed: 10 years ago
Flags: needinfo?(jvehent)
Resolution: --- → FIXED
(In reply to Julien Vehent [:ulfr] from comment #15) > I provided a dump of the filenames in those S3 buckets to infosec. This bug > can be closed and another bug will be opened if more files need to be > removed. Hi Julien, Thanks for your comment. Am I allowed to write a blog post about this issue? Regards, Adel
Hi @all, I would like to know if this issue qualifies for any bounty/thanks under hall of fame/ and if I'm allowed to write blog post about this issue?
@Adel; it does qualify for bounty consideration (notice the sec-bounty:? flag in the bug header). The bounty committee meets weekly to discuss resolved bugs and if a bounty is granted it will be marked sec-bounty: + We are a bit behind on bounty meetings due to a company work week and travel schedules, thanks for you patience. As far as blog post, the bug is currently marked confidential. If/when this flag is removed then the issue is considered public and can therefore be discussed publicly.
Thanks a lot for the update. Best Regards, Adel
Group: websites-security
Flags: sec-bounty? → sec-bounty+
You need to log in before you can comment on or make changes to this bug.