Self Signed SSL Certificate on m.mozilla.org
Categories
(Websites :: Other, task)
Tracking
(Not tracked)
People
(Reporter: mahetagaurangm2, Unassigned)
References
()
Details
(Keywords: reporter-external, Whiteboard: [reporter-external] [web-bounty-form] [verif?])
Helllo Team
I Keyur Maheta found security issue in your system
TiTLE :
Self Signed SSL Certificate
Step To Reproduce :
https://m.mozilla.org
Best regards,
Keyur
Comment 1•4 years ago
|
||
Hi Keyur,
Can you please provide a bit more detail about the vulnerability and the steps to reproduce it?
Thanks
Updated•4 years ago
|
Comment 2•4 years ago
|
||
Here is the TLS certificate being used on m.mozilla.org
Showing certificate for domain name m.mozilla.org
depth=0 O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
verify error:num=21:unable to verify the first certificate
verify return:1
DONE
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
de:eb:bf:81:32:b2:20:8d:c4:67:89:c2:b8:74:44:42
Signature Algorithm: sha256WithRSAEncryption
Issuer: O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
Validity
Not Before: Jul 25 09:56:20 2022 GMT
Not After : Jul 25 09:56:20 2023 GMT
Subject: O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:bd:8b:c1:45:01:ef:f9:bb:c1:d4:8c:8f:ff:08:
2a:fc:bd:3e:8d:30:80:d6:85:05:93:75:40:16:d7:
41:31:61:f7:e4:50:63:92:b7:66:d4:7c:3c:71:4d:
54:b9:58:e0:30:b1:19:79:a3:1f:76:a3:d5:91:34:
22:9c:d9:c8:6b:c3:a5:35:bd:8d:25:eb:d4:4f:c0:
30:c3:b3:e3:c6:f2:f8:64:a6:bb:d1:3d:62:e4:9c:
ab:7b:d2:e8:46:18:80:ae:64:a9:ca:fc:93:e4:76:
aa:c6:15:ae:b9:38:84:76:31:fe:fd:2a:be:ea:a7:
70:ea:41:5b:f8:24:e7:c6:7f:f0:8d:cd:c0:24:b4:
17:05:0b:89:21:ff:40:ae:66:77:02:b3:34:bb:54:
5a:b5:9c:a9:6d:c2:59:2a:03:90:a7:4d:5e:49:d0:
51:1f:26:1d:92:d9:19:55:44:43:44:cc:07:c4:12:
de:60:be:5f:cd:9d:9e:b2:5a:04:af:5c:3d:18:69:
e1:9d:dc:44:4d:78:de:34:18:27:03:6b:d6:82:94:
04:99:18:c5:d3:eb:0f:60:44:d4:4b:6e:c6:12:dd:
38:ec:1d:34:fd:2a:05:e6:11:e1:95:a8:7e:58:b0:
3b:75:51:75:a8:3f:10:19:af:e9:c9:34:ec:79:d3:
18:03
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Alternative Name:
DNS:ingress.local
Signature Algorithm: sha256WithRSAEncryption
8b:4d:b4:c0:23:91:cc:68:ce:f7:1a:f5:e7:28:e2:9d:c6:bb:
9d:ce:27:14:4f:8b:aa:55:b0:2d:b7:61:22:f7:00:6a:9d:a0:
38:76:17:9b:dd:7c:2f:f2:3a:ab:29:aa:3d:d8:ca:14:03:bf:
20:d2:6b:86:c3:5f:28:04:1f:f0:c7:83:bc:d1:96:f8:3d:76:
0a:19:b0:be:75:c1:80:35:cd:7b:1b:a2:10:dc:e7:b0:55:39:
cd:83:b2:d0:6a:bd:75:ca:b0:ad:5f:e7:66:6c:ce:51:86:0d:
15:f6:f2:73:22:95:f1:59:5f:ae:32:02:79:e1:43:4d:ef:d4:
76:db:a3:09:16:fe:df:1b:60:3f:a5:79:39:d6:8e:f7:99:1d:
69:91:e1:05:9f:2b:7b:35:af:79:29:21:2c:25:dd:b5:ac:cb:
29:e9:5f:4b:5a:19:2c:50:53:b6:a9:cb:66:7d:e4:85:58:f9:
b6:c7:9c:07:17:b3:c8:5b:2a:70:81:ec:1f:f9:b8:06:93:90:
f5:2d:40:16:51:ca:98:1f:11:56:02:b0:90:41:32:9f:15:d3:
01:6c:b7:b9:02:77:0e:25:c6:d5:96:0b:da:d9:67:94:50:06:
e0:2d:28:ab:de:44:40:97:84:af:05:4d:9a:69:1d:48:fd:19:
7d:70:c3:ab
Comment 3•4 years ago
|
||
This domain doesn't host any web content, it's used as the from address for mailing list and newsletter emails. I suspect the thing to do here is to stop running nginx on this ec2 instance, or if indeed there is a need to host content on this web server, then to use letsencrypt to provision a certificate
Updated•4 years ago
|
Updated•4 years ago
|
Comment 4•4 years ago
|
||
The https://m.mozilla.org/ service was decommissioned a while ago but the A record was not removed from our DNS. The record is now removed.
Thank you again for reporting this issue to us. Now that the issue is fixed, the bug bounty team will be reviewing your report over the upcoming weeks to determine whether this report is eligible for reward. It may take up to 3 weeks but know that we have not forgotten this ticket, we have a tracking system and a review cadence that will ensure that all potentially bounty eligible reports get reviewed and acted on.
Thanks,
Frida
Comment 5•4 years ago
|
||
There was no security impact to this since we did not use this site. It was definitely a bug/mistake, but not eligible for a bug bounty
Updated•2 years ago
|
Description
•