漏洞描述
Firebase debug log file was exposed.
id: firebase-debug-log
info:
name: Firebase Debug Log File Exposure
author: Hardik-Solanki
severity: low
description: Firebase debug log file was exposed.
reference:
- https://github.com/maurosoria/dirsearch/blob/master/db/dicc.txt
metadata:
verified: true
max-request: 1
github-query: filename:firebase-debug.log
tags: exposure,firebase,logs,debug,vuln
http:
- method: GET
path:
- "{{BaseURL}}/firebase-debug.log"
matchers-condition: and
matchers:
- type: word
part: body
words:
- '[debug]'
- 'firebase'
- 'googleapis.com'
condition: and
- type: status
status:
- 200
# digest: 4b0a00483046022100f7cdc0f1c1ef0070164bb3d74beab0ef345065b79b85e0ed0810a5ed967962e30221008f37ed10aa0d76eb323b1f5500fd455d4933c6d9d40d2f37c014898a0c981404:922c64590222798bb761d5b6d8e72950