Skip to content

fsp - Firestore Database Vulnerability Scanner Using APKs

Notifications You must be signed in to change notification settings

takito1812/FireStorePwn

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 

Repository files navigation


FireStorePwn (fsp)

Firestore Database Vulnerability Scanner Using APKs


fsp scans an APK and checks the Firestore database for rules that are not secure, testing with or without authentication.

If there are problems with the security rules, attackers could steal, modify or delete data and raise the bill.

How it works

fsp-flow

Install fsp

sudo wget https://raw.githubusercontent.com/takito1812/FireStorePwn/main/fsp -O /bin/fsp
sudo chmod +x /bin/fsp

Running fsp

Scanning an APK without authentication

fsp app.apk

Scanning an APK with authentication

With email and password.

fsp app.apk test@test.com:123456

With a token.

fsp app.apk eyJhbGciO...