Why hack when it's leaking? How we attacked google firestore customers.

SUB-ZER0

Infinity Member
Golden Member
Joined
December 4, 2025
Messages
1,352
Reaction score
21,304
Points
113
  • Thread Author
  • #1
Firestore security rules are configured to allow public access (i.e., allow read, write: if true , you can use a curl command to test if the collection is publicly readable. You would make a GET request to the Firestore REST API.

To see this hidden content, you need to "Reply & React" with one of the following reactions: Like, Love, Haha, Wow
 
  • Tags
    cybersecurity data_leak google_firestore