attackndefense Profile Banner
Attack and Defense Profile
Attack and Defense

@attackndefense

Followers
1K
Following
17
Media
4
Statuses
138

@[email protected] - Mozilla's Security Internals for Security Engineers, Security Researchers, and Bug Bounty Hunters.

Joined February 2020
Don't wanna be here? Send us removal request.
@attackndefense
Attack and Defense
5 years
Please report bugs. If you - or someone else - improves exploitability after initial report, the bounty will be increased. If you're second reporter, you will be pro-rated. I guess I can only speak for our bounty program but come on industry, you can do better. #bugbountytips
@mcipekci
Mustafa Can İPEKÇİ
5 years
Do not report open redirects without fully analyzing and seeing potentials of it. Thanks to random guy who reported open redirect, our report for full SSRF leaking client secret of integration claimed dupe. Again: do not report open redirects #bugbountytips
3
0
9
@attackndefense
Attack and Defense
3 days
(This is not the Firefox Security team, so we won't be able to answer a lot of the typical questions here)
0
0
0
@attackndefense
Attack and Defense
6 months
We just published the Q2 2025 edition of the Firefox Security and Privacy newsletter. Highlights: * CHIPS * Webcompat improvements * Better HTTPS error pages * Firefox Relay integration ...and much more. https://t.co/uxxMw5gRuU
attackanddefense.dev
Welcome to the Q2 2025 edition of the Firefox Security and Privacy newsletter!
0
1
1
@attackndefense
Attack and Defense
6 months
Did you know that all of our good stuff is also available elsewhere? Follow us on Mastodon at https://t.co/yJ7EtZOQJd or keep refreshing our site at
0
0
0
@attackndefense
Attack and Defense
6 months
We just updated our bug bounty hall of fame to include the great security researchers from the last two quarters. Thank you for securing the best #Firefox yet :) https://t.co/zRlAT45pKa
Tweet card summary image
mozilla.org
0
1
5
@kinugawamasato
Masato Kinugawa
6 months
https://t.co/fIkkSptNXY This is a big change for DOM Clobberers. Firefox Nightly no longer allows native document properties to be overwritten by elements with a name attr, e.g.: <img src=a name=currentScript> <script> alert(document.currentScript)// HTMLScriptElement </script>
bugzilla.mozilla.org
RESOLVED (tschuster) in Core - DOM: Core & HTML. Last updated 2025-07-23.
3
21
158
@evilpies
Tom Schuster
7 months
@garethheyes @kinugawamasato Good find. This is now fixed @FirefoxNightly. Sorry, no fun allowed.
1
1
3
@attackndefense
Attack and Defense
1 year
We updated our Firefox Bug Bounty Hall of Fame for Q4 of 2024. 🏆👏 Thank you to the many folks who helped keep Firefox secure!
Tweet card summary image
mozilla.org
0
1
2
@firefox
Firefox 🔥
1 year
We're turning the big 2-0 this year! Help us celebrate by sharing your best Firefox fan art 🔥 tag us or use #FirefoxArt by 11/01 so we don't miss it. (you just might score some fun surprises too...)
14
30
303
@attackndefense
Attack and Defense
1 year
If you haven't updated Firefox in a while, do it now. We have fixed a high-severity security vulnerability that is apparently exploited in the wild. We shipped this within 25 hours after being reported to us. https://t.co/zx6sebvXK9
0
3
9
@attackndefense
Attack and Defense
2 years
You can avoid your bugs to be of decreased value by: 1. Demonstrate code execution with an exploit 2. Find a spoof in the existing address bar. Learn more at https://t.co/6ivGnK9vt1 &
0
0
2
@attackndefense
Attack and Defense
2 years
Minor update to our our linked Security Severity Ratings and therefore the bug bounty program. We are decreasing the severity of 1. Memory safety issues that require just one _specific_ allocation to fail. 2. Full screen prompt spoofs.
1
1
2
@attackndefense
Attack and Defense
2 years
.@freddyb will be at #Offensivecon24 in Berlin. Let us know if you want to meet up to talk about browser/ web security.
0
0
1
@attackndefense
Attack and Defense
2 years
P.S: We pay up to $20k for a good sandbox escape. Take a look at https://t.co/lTEoqzuQ4U for our bounty program. If you want to learn how to find these kinds of bugs, @LiveOverflow made a great video at
0
1
5
@attackndefense
Attack and Defense
2 years
Kudos to all the countless people postponing their sleep and working towards resolving this so quickly! Really impressive teamwork again. Also, kudos to Manfred for pwning Firefox again :)
1
0
3
@attackndefense
Attack and Defense
2 years
Last Thursday, @_manfp demonstrated a security exploit targeting Firefox 124 at pwn2own. Within 21 hours, we published Firefox 124.0.1 (and Firefox ESR 115.9.1) containing the security fix. Please update your foxes! 🦊
1
5
40
@attackndefense
Attack and Defense
2 years
Just report it in January, joernchen… 😉
@joernchen
joernchen
2 years
Happy Holidays Some people get a well deserved break from me. I‘m doing my traditional Christmas bug hunting elsewhere ;).
1
0
3