Periscope-all Firebase database takeover
Critical
Vulnerability Details
Hello,
I found one public Firebase database of periscope.tv and I can able to insert data to this database and i only used it once for the testing purposes, so other database queries also possible.
Please follow the below link to check the inserted test data.
###Periscope-all Firebase URL :-
https://█████████/.json
## Impact
This is quite serious because by using this database attacker can use this for malicious purposes and also an attacker can track this database if periscope uses it for future perspective and at that time it will be much easier for the attacker to steal the data from this repository and later it will harm the reputation of the Periscope.
So please immediately change the rule of the database to private so that nobody can able to access it outside.
Thanks
Deeptiman Pattnaik
Actions
View on HackerOneReport Stats
- Report ID: 684099
- State: Closed
- Substate: resolved
- Upvotes: 44