Loading HuntDB...

Periscope-all Firebase database takeover

Critical
X
X (Formerly Twitter)
Submitted None
Reported by deeptiman

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
Hello, I found one public Firebase database of periscope.tv and I can able to insert data to this database and i only used it once for the testing purposes, so other database queries also possible. Please follow the below link to check the inserted test data. ###Periscope-all Firebase URL :- https://█████████/.json ## Impact This is quite serious because by using this database attacker can use this for malicious purposes and also an attacker can track this database if periscope uses it for future perspective and at that time it will be much easier for the attacker to steal the data from this repository and later it will harm the reputation of the Periscope. So please immediately change the rule of the database to private so that nobody can able to access it outside. Thanks Deeptiman Pattnaik

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic