Android Firebase Takeover Vulnerability of 2023 ( Full Tutorial ) | bug bounty POC 2023

Поділитися
Вставка
  • Опубліковано 9 лис 2024

КОМЕНТАРІ • 39

  • @Free.Education786
    @Free.Education786 Рік тому +3

    Please, if possible, cover these advanced topics like How to bypass Drupal CMS or other secured CMS? How to bypass HARD WAF protection that stops HTML, SQL, and XSS injection payloads? Payload single-double-triple encoding using Cyber-Chef? How to find the real origin IP of secured websites behind Cloudflare, Akamai, ModSecurity, AWS CDN, etc.,? How to bypass Hard WAF using SQLMAP or Burpsuite? How to find hidden, vulnerable parameters and endpoints inside the .js and .jason files? How to find hidden admin pages, cPanel pages, and WHM pages ? Please cover these important topics. Thanks

  • @livebughunting9393
    @livebughunting9393 Рік тому +2

    Great bro, today i learn new trick ❤❤❤

  • @partha4891
    @partha4891 Рік тому +1

    Great

  • @onlyfybyXING
    @onlyfybyXING Рік тому +1

    thank you

  • @avatoruncharted1420
    @avatoruncharted1420 Рік тому +1

    What a song❤❤❤❤🎉🎉🎉

  • @candid_photoshoot
    @candid_photoshoot Рік тому +1

    Tnx bro ❤❤❤❤🎉

  • @CyberXSpyware
    @CyberXSpyware Рік тому +1

    I want ask u how to bypass WP security hardening with sqlmap?

    • @THEBBH
      @THEBBH  Рік тому

      Oky i will try to make it.

  • @partha4891
    @partha4891 Рік тому +1

    Bro which is your main account?

  • @FS0ci3ty
    @FS0ci3ty Рік тому +1

    Telegram channel ki link expire hai, update kro

    • @THEBBH
      @THEBBH  Рік тому

      Thanks for the confirmation Updated bro

  • @LEOSTRIBE
    @LEOSTRIBE Рік тому +1

    how did you find that there are these 3 databases : name , email and role?

    • @THEBBH
      @THEBBH  Рік тому +1

      Boss please watch carefully the video.

    • @LEOSTRIBE
      @LEOSTRIBE Рік тому +1

      @@THEBBH not getting it, pls explain that how did you find out that there are these 3 tables ?

    • @THEBBH
      @THEBBH  Рік тому

      I have to inject on them bro. Firstly i fetch the apk then i have to find firebase link without the was without (.json) like domaim.firebaseio.com/(here i put the .json) and then i see the data is nothing like the website will give the null i have to put them my data and check right permissions is there or not. After successfully exploit it's means i have a read and write permission. The three columns are created by me to inject the data

  • @priyachowdhary140
    @priyachowdhary140 Рік тому +1

    Works only on Firebase url like there are several /.json files ?? And how did you find the url what tool you used??

    • @cimangongfc1515
      @cimangongfc1515 Рік тому +1

      I think he using google dork

    • @cimangongfc1515
      @cimangongfc1515 Рік тому +1

      It same like you wanna deface PoC RFI, the dork find directory upload, but on this case, this guy using like inurl: firebase/.json or something else

    • @THEBBH
      @THEBBH  Рік тому

      No buddy that's the apk file. 😂

    • @THEBBH
      @THEBBH  Рік тому

      Yes, when yo do the pentesting on apk app then this is the first thing you need to check

  • @The12-28
    @The12-28 Рік тому +1

    It's not fixed yet, how you make the poc public?

    • @THEBBH
      @THEBBH  Рік тому +1

      I already have permission to make videos on it.

  • @franvandenboschee9487
    @franvandenboschee9487 Рік тому +1

    Can you pass the new telegram link? thx

    • @THEBBH
      @THEBBH  Рік тому

      t.me/+RYXyf9wY3BIzOWNl

  • @josephblack7408
    @josephblack7408 Рік тому +1

    telegram invite link expired

    • @THEBBH
      @THEBBH  Рік тому

      t.me/+RYXyf9wY3BIzOWNl

  • @learn-with-noob-007
    @learn-with-noob-007 Рік тому +1

    How you got firebase?

    • @THEBBH
      @THEBBH  Рік тому

      Just Decompile the Apk and Check the strings.xml file on it and search firebase link. That's Link look like without /.json then put it on the url and check it.

  • @candid_photoshoot
    @candid_photoshoot Рік тому +1

    Are u full time bug hunter ?

  • @stux4961
    @stux4961 Рік тому +1

    Invite link for telegram - expired

    • @THEBBH
      @THEBBH  Рік тому +1

      t.me/+RYXyf9wY3BIzOWNl

  • @princemedhavichaturvedi6161
    @princemedhavichaturvedi6161 Рік тому +1

    Great