firebase-debug-log: Firebase Debug Log File Exposure

日期: 2025-08-01 | 影响软件: Firebase Debug Log | POC: 已公开

漏洞描述

Firebase debug log file was exposed.

PoC代码[已公开]

id: firebase-debug-log

info:
  name: Firebase Debug Log File Exposure
  author: Hardik-Solanki
  severity: low
  description: Firebase debug log file was exposed.
  reference:
    - https://github.com/maurosoria/dirsearch/blob/master/db/dicc.txt
  metadata:
    verified: true
    max-request: 1
    github-query: filename:firebase-debug.log
  tags: exposure,firebase,logs,debug,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/firebase-debug.log"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '[debug]'
          - 'firebase'
          - 'googleapis.com'
        condition: and

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100f7cdc0f1c1ef0070164bb3d74beab0ef345065b79b85e0ed0810a5ed967962e30221008f37ed10aa0d76eb323b1f5500fd455d4933c6d9d40d2f37c014898a0c981404:922c64590222798bb761d5b6d8e72950