hogum
mozilla.org

mozilla.org security report

Certificate, security headers, email authentication, DNS, registration, and exposed hosts — from public sources.

14risk

Low

Minor observations only.

0Critical
0High
0Medium
21Low
1Info
Collected 4.2sfrom cache
  1. Certificate Transparency448
  2. DNS resolution16
  3. Network ownership0
  4. CDN / WAF detection0
  5. Exposed ports & CVEs45
  6. Registration
  7. DNS posture4
  8. Email authentication2
  9. Certificate
  10. Security headers5
  11. Archived URLs
  12. Analysis22
  • noteFound 448 hostnames; resolving the first 400.
  • noteFound 400 hostnames; this runtime allows 50 outbound requests per scan, so the 21 most likely to matter were resolved.
  • noteCertificate inspection is unavailable in this runtime.
  • noteNetwork ownership lookup is unavailable in this runtime; ASN and org are omitted.
  • noteCDN/WAF detection is unavailable in this runtime.
  • note2 hosts were identified as CDN/edge infrastructure from ASN ownership rather than a cdncheck fingerprint.
final https://www.mozilla.org/status 200time 231msstack cloudflare
  • http:// redirects to https://
  • Strict-Transport-Security
    max-age=31536000
  • Content-Security-Policy
    style-src 'self' 'unsafe-inline' cdn.transcend.io transcend-cdn.com www.mozilla.org; form-action 'self' https://abdri3ttkb.execute-api.us-east-2.amazonaws.com h…
  • Clickjacking protection
    DENY
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
    strict-origin-when-cross-origin
  • Permissions-Policyoptional
  • security.txt publishedoptional — tells researchers where to report bugs
  • Receives mail via 4 servers
  • !SPFends in ~all
    v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:_spf.mozilla.com include:_spf.google.com include:spf.fundraiseup.com ~all
  • DMARCp=reject
    v=DMARC1; p=reject; pct=100; adkim=r; aspf=r; rua=mailto:dmarc_agg@vali.email,mailto:dmarc@mozilla.com
  • !MTA-STSinbound mail can be downgraded to plaintext
  • !DNSSECanswers can be forged
  • CAA
    0 issue "letsencrypt.org" · 0 issue "certainly.com" · 0 issue "amazon.com" · 0 iodef "mailto:foxsec+caaiodef@mozilla.com" · 0 issue "sectigo.com" · 0 issue "digicert.com" · 0 issue "amazontrust.com" · 0 issue "awstrust.com" · 0 issue "amazonaws.com" · 0 issue "pki.goog" · 0 issue "comodoca.com"
  • IPv6 (AAAA)
  • 4 nameservers
AddressPortsCVEsEdgeNetwork
141.193.213.11
80443205220532082208320862087+5
0Cloudflare~
141.193.213.10
80443205220532082208320862087+5
0Cloudflare~
35.190.14.201
80443
0direct
34.36.7.128
80443
0direct
34.104.33.82
80443
0direct
151.101.1.91
80443
0direct
151.101.65.91
80443
0direct
151.101.129.91
80443
0direct
151.101.193.91
80443
0direct
35.212.137.69
4435672
0direct
35.212.221.146
4435672
0direct
35.212.157.109
443
0direct
Archived URLs

Endpoints the Wayback Machine has kept — config files, backups, scripts. Slow to fetch, so it is here on request.