{"repo":"0xbigshaq/firepwn-tool","free":true,"listed":false,"github":"https://github.com/0xbigshaq/firepwn-tool","clone":"git clone https://github.com/0xbigshaq/firepwn-tool.git","description":"Firepwn is a tool made for testing the Security Rules of a firebase application.","language":"TypeScript","stars":673,"topics":["firebase","firebase-security","firebase-database","firestore","firebase-pentest"],"license":"GPL-3.0","category":"auth-billing-email","readme_excerpt":"firepwn A tool for testing Firebase Security Rules by simulating real client SDK behavior. Unlike most Firebase pentest scripts that rely on the REST API, firepwn uses the actual Firebase Client SDK to test both authentication and authorization across multiple Google services. Features Firebase Initialization Configure a target project by entering its firebaseConfig values ( apiKey , authDomain , databaseURL , projectId , storageBucket ). Supports both individual form fields and pasting a raw JSON/JS config object. Authentication Supports multiple Firebase Authentication methods: - Email/Password - sign in with existing credentials or register a new account - Google OAuth - paste an oauthIdToken captured from the target app's sign-in flow (e.g. from browser DevTools) to assume a Google session - MFA (SMS) - complete multi-factor authentication challenges with SMS verification codes - Anonymous - sign in anonymously to test rules that allow unauthenticated or anonymous users Firestore Database Full CRUD operations on Firestore: - Get - with document limit, sort order, and query filters ( == , , = , array-contains , in ) - Set - create documents or overwrite existing ones (with optional merge mode) - Update - modify specific fields in existing documents - Delete - remove documents Supports nested collections/subcollections. Cloud Storage Interact with Firebase Storage buckets: - List files and directories - Upload / Download files - Delete files - Get metadata for stored object","default_branch":null,"files":null,"tree":[],"storefront":"/r/0xbigshaq","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0xbigshaq/firepwn-tool/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}