From 085791de3b534e6d0ad9b4ef600f5a29ff18c58f Mon Sep 17 00:00:00 2001 From: Hardik Solanki <49536512+HardikSolanki96@users.noreply.github.com> Date: Sat, 10 Dec 2022 13:56:10 +0000 Subject: [PATCH] Create firebase-debug-log.yaml --- exposures/logs/firebase-debug-log.yaml | 30 ++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 exposures/logs/firebase-debug-log.yaml diff --git a/exposures/logs/firebase-debug-log.yaml b/exposures/logs/firebase-debug-log.yaml new file mode 100644 index 0000000000..70634e4216 --- /dev/null +++ b/exposures/logs/firebase-debug-log.yaml @@ -0,0 +1,30 @@ +id: firebase-debug-log + +info: + name: Firebase Debug Log File Exposure + author: Hardik-Solanki + severity: low + metadata: + verified: true + github-query: filename:firebase-debug.log + reference: + - https://github.com/maurosoria/dirsearch/blob/master/db/dicc.txt + tags: exposure,firebase,log,debug + +requests: + - method: GET + path: + - "{{BaseURL}}/firebase-debug.log" + + matchers-condition: and + matchers: + - type: word + part: body + words: + - '[debug]' + - 'googleapis.com' + condition: and + + - type: status + status: + - 200