daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

firebase-database.md (1312B)


      1 ---
      2 title: "Firebase Database"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/buckets/firebase-database.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/buckets/firebase-database.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Firebase Database
     14 
     15 ## What is Firebase
     16 
     17 Firebase is a backend-as-a-service platform commonly used by mobile and web applications. Its Realtime Database is a cloud-hosted NoSQL database that stores data as JSON and synchronizes changes with connected clients. Applications commonly access it through mobile and web SDKs or its REST interface, while Firebase Security Rules determine which reads and writes are allowed.<sup>[[1]](#references)</sup>
     18 
     19 For enumeration and security-testing techniques, see the dedicated HackTricks Cloud guide.<sup>[[2]](#references)</sup>
     20 
     21 ## References
     22 
     23 - [1] [Firebase Documentation - Realtime Database](https://firebase.google.com/docs/database)
     24 - [2] [HackTricks Cloud - GCP Firebase enumeration](https://cloud.hacktricks.wiki/en/pentesting-cloud/gcp-security/gcp-services/gcp-firebase-enum.html)