Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Firebase #128

Open
random-robbie opened this issue Jan 6, 2020 · 5 comments
Open

Firebase #128

random-robbie opened this issue Jan 6, 2020 · 5 comments
Labels
not vulnerable Someone has made it very clear that this service is not vulnerable to subdomain takeovers.

Comments

@random-robbie
Copy link
Contributor

Service name

Google Firebase

Can i take it over

No - requires txt record to authenticate it so it's not possible.

@melardev
Copy link

melardev commented Jan 6, 2020

funny, I was just trying a few hours ago to take over a firebase app, I could not, but what I noticed is that the TXT record is the same for the same custom domain in the same user session, I did not test further, I was lazy, the remaining test is, to check if the TXT record is the same for the same custom domain after logout/#, and most importantly across any account, because if the victim is given a TXT record, but you are given another one for the same vulnerable.example.com, then it is not vulnerable.

@melardev
Copy link

melardev commented Jan 6, 2020

@random-robbie This is the TXT record I get when I try to add github.com:
google-site-verification=_hFoiuxEK5rlpZZfR8DgLq48UvrqRleu6cat5EBe3x0
Can you tell me if you get the same?

@shoeper
Copy link

shoeper commented Feb 8, 2020

I get a different one: google-site-verification=vENMi3mjve0BU8HfQLJQ3ts8B9U8IF3UDBdWpN8Y1ls

@melardev
Copy link

@shoeper Thanks for confirming. I keep getting the TXT I said at the beginning, so I think we get a constant TXT per account and hostname, that would mean it is not vulnerable since other accounts get a different TXT value.

@EdOverflow EdOverflow added the not vulnerable Someone has made it very clear that this service is not vulnerable to subdomain takeovers. label May 18, 2020
@ankurtehlan
Copy link

Can it is possible to takeover firebase subdomain

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
not vulnerable Someone has made it very clear that this service is not vulnerable to subdomain takeovers.
Projects
None yet
Development

No branches or pull requests

6 participants
@random-robbie @shoeper @melardev @EdOverflow @ankurtehlan and others