-
-
Notifications
You must be signed in to change notification settings - Fork 735
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Firebase #128
Comments
funny, I was just trying a few hours ago to take over a firebase app, I could not, but what I noticed is that the TXT record is the same for the same custom domain in the same user session, I did not test further, I was lazy, the remaining test is, to check if the TXT record is the same for the same custom domain after logout/#, and most importantly across any account, because if the victim is given a TXT record, but you are given another one for the same vulnerable.example.com, then it is not vulnerable. |
@random-robbie This is the TXT record I get when I try to add github.com: |
I get a different one: |
@shoeper Thanks for confirming. I keep getting the TXT I said at the beginning, so I think we get a constant TXT per account and hostname, that would mean it is not vulnerable since other accounts get a different TXT value. |
Can it is possible to takeover firebase subdomain |
Service name
Google Firebase
Can i take it over
No - requires txt record to authenticate it so it's not possible.
The text was updated successfully, but these errors were encountered: