Fighting The Unknown

I grew up with my mom being sick, a lot. Some of my earliest memories are when I would go over to friends house to do school because my mom was too sick or when I would always visit my mom in bed. I…

Smartphone

独家优惠奖金 100% 高达 1 BTC + 180 免费旋转




Firebase Allow Anonymous Read and Write Access

Description:

A simple Python Exploit to Write Data to Insecure/vulnerable firebase databases! Commonly found inside Mobile Apps. If the owner of the app have set the security rules as true for both “read” & “write” an attacker can probably dump database and write his own data to firebase db.

How to Find the Firebase URLs:

Firebase Scanner:

2. More than 3,000 apps were leaking data from 2,300 unsecured servers. Of these, 975 apps were in active customer environments.

Firebase-Exploit:

python Firebase-Write-Permission-Exploit.py

Sample POC

Mitigation:

Application should restrict the read and write access permission

Add a comment

Related posts:

3 Types of Boundaries to Boost Your Mental Health

Life is too short to be hanging out with negative people — even if they’re family. Sarcasm, pessimism, cynicism, one-upping, constant complaining, chronic discontent, blamey, shamey, judgey, negative…

Upgrade your Torus Wallet with OpenLogin

We just released OpenLogin across all our platforms (read the announcement here), including Torus Wallet! Our Torus Wallet users can now enjoy seamless Face/TouchID authentication that OpenLogin…

You are not focused enough

In our highly dynamic and rapidly changing world, standing out of the crowd and creating something much bigger than yourself requires one major thing: focus — such a simple word; such a powerful…