Closed Bug 1783134 Opened 4 years ago Closed 4 years ago

Self Signed SSL Certificate on m.mozilla.org

Categories

(Websites :: Other, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: mahetagaurangm2, Unassigned)

References

()

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Helllo Team
I Keyur Maheta found security issue in your system

TiTLE :

Self Signed SSL Certificate

Step To Reproduce :
https://m.mozilla.org

Best regards,
Keyur

Flags: sec-bounty?

Hi Keyur,

Can you please provide a bit more detail about the vulnerability and the steps to reproduce it?

Thanks

Summary: vulnerability Report - 1000755 → Self Signed SSL Certificate on m.mozilla.org

Here is the TLS certificate being used on m.mozilla.org

Showing certificate for domain name m.mozilla.org
depth=0 O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
verify error:num=21:unable to verify the first certificate
verify return:1
DONE
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            de:eb:bf:81:32:b2:20:8d:c4:67:89:c2:b8:74:44:42
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
        Validity
            Not Before: Jul 25 09:56:20 2022 GMT
            Not After : Jul 25 09:56:20 2023 GMT
        Subject: O = Acme Co, CN = Kubernetes Ingress Controller Fake Certificate
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
                Modulus:
                    00:bd:8b:c1:45:01:ef:f9:bb:c1:d4:8c:8f:ff:08:
                    2a:fc:bd:3e:8d:30:80:d6:85:05:93:75:40:16:d7:
                    41:31:61:f7:e4:50:63:92:b7:66:d4:7c:3c:71:4d:
                    54:b9:58:e0:30:b1:19:79:a3:1f:76:a3:d5:91:34:
                    22:9c:d9:c8:6b:c3:a5:35:bd:8d:25:eb:d4:4f:c0:
                    30:c3:b3:e3:c6:f2:f8:64:a6:bb:d1:3d:62:e4:9c:
                    ab:7b:d2:e8:46:18:80:ae:64:a9:ca:fc:93:e4:76:
                    aa:c6:15:ae:b9:38:84:76:31:fe:fd:2a:be:ea:a7:
                    70:ea:41:5b:f8:24:e7:c6:7f:f0:8d:cd:c0:24:b4:
                    17:05:0b:89:21:ff:40:ae:66:77:02:b3:34:bb:54:
                    5a:b5:9c:a9:6d:c2:59:2a:03:90:a7:4d:5e:49:d0:
                    51:1f:26:1d:92:d9:19:55:44:43:44:cc:07:c4:12:
                    de:60:be:5f:cd:9d:9e:b2:5a:04:af:5c:3d:18:69:
                    e1:9d:dc:44:4d:78:de:34:18:27:03:6b:d6:82:94:
                    04:99:18:c5:d3:eb:0f:60:44:d4:4b:6e:c6:12:dd:
                    38:ec:1d:34:fd:2a:05:e6:11:e1:95:a8:7e:58:b0:
                    3b:75:51:75:a8:3f:10:19:af:e9:c9:34:ec:79:d3:
                    18:03
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Subject Alternative Name: 
                DNS:ingress.local
    Signature Algorithm: sha256WithRSAEncryption
         8b:4d:b4:c0:23:91:cc:68:ce:f7:1a:f5:e7:28:e2:9d:c6:bb:
         9d:ce:27:14:4f:8b:aa:55:b0:2d:b7:61:22:f7:00:6a:9d:a0:
         38:76:17:9b:dd:7c:2f:f2:3a:ab:29:aa:3d:d8:ca:14:03:bf:
         20:d2:6b:86:c3:5f:28:04:1f:f0:c7:83:bc:d1:96:f8:3d:76:
         0a:19:b0:be:75:c1:80:35:cd:7b:1b:a2:10:dc:e7:b0:55:39:
         cd:83:b2:d0:6a:bd:75:ca:b0:ad:5f:e7:66:6c:ce:51:86:0d:
         15:f6:f2:73:22:95:f1:59:5f:ae:32:02:79:e1:43:4d:ef:d4:
         76:db:a3:09:16:fe:df:1b:60:3f:a5:79:39:d6:8e:f7:99:1d:
         69:91:e1:05:9f:2b:7b:35:af:79:29:21:2c:25:dd:b5:ac:cb:
         29:e9:5f:4b:5a:19:2c:50:53:b6:a9:cb:66:7d:e4:85:58:f9:
         b6:c7:9c:07:17:b3:c8:5b:2a:70:81:ec:1f:f9:b8:06:93:90:
         f5:2d:40:16:51:ca:98:1f:11:56:02:b0:90:41:32:9f:15:d3:
         01:6c:b7:b9:02:77:0e:25:c6:d5:96:0b:da:d9:67:94:50:06:
         e0:2d:28:ab:de:44:40:97:84:af:05:4d:9a:69:1d:48:fd:19:
         7d:70:c3:ab

This domain doesn't host any web content, it's used as the from address for mailing list and newsletter emails. I suspect the thing to do here is to stop running nginx on this ec2 instance, or if indeed there is a need to host content on this web server, then to use letsencrypt to provision a certificate

Status: UNCONFIRMED → NEW
Ever confirmed: true
Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED

The https://m.mozilla.org/ service was decommissioned a while ago but the A record was not removed from our DNS. The record is now removed.

Thank you again for reporting this issue to us. Now that the issue is fixed, the bug bounty team will be reviewing your report over the upcoming weeks to determine whether this report is eligible for reward. It may take up to 3 weeks but know that we have not forgotten this ticket, we have a tracking system and a review cadence that will ensure that all potentially bounty eligible reports get reviewed and acted on.

Thanks,
Frida

There was no security impact to this since we did not use this site. It was definitely a bug/mistake, but not eligible for a bug bounty

Group: websites-security
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.