Periscope-all Firebase database takeover
Critical
X
X (Formerly Twitter)
Submitted None
Actions:
Reported by
deeptiman
Vulnerability Details
Technical details and impact analysis
Hello,
I found one public Firebase database of periscope.tv and I can able to insert data to this database and i only used it once for the testing purposes, so other database queries also possible.
Please follow the below link to check the inserted test data.
###Periscope-all Firebase URL :-
https://█████████/.json
## Impact
This is quite serious because by using this database attacker can use this for malicious purposes and also an attacker can track this database if periscope uses it for future perspective and at that time it will be much easier for the attacker to steal the data from this repository and later it will harm the reputation of the Periscope.
So please immediately change the rule of the database to private so that nobody can able to access it outside.
Thanks
Deeptiman Pattnaik
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic