Zum Hauptinhalt springen
Dieser Inhalt ist noch nicht in Ihrer Sprache verfügbar und wird auf Englisch angezeigt.

Firebase Apk Scanner

Plugin Verifiziert Aktiv
Teil von:Trailofbits

Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.

1 Skill 0 MCPs
Zweck

To automate the security assessment of Android applications utilizing Firebase, identifying critical misconfigurations that could lead to data breaches or unauthorized access.

Funktionen

  • Decompiles Android APKs
  • Extracts Firebase configuration from multiple sources
  • Tests Firebase authentication, databases, storage, and cloud functions
  • Reports findings with remediation guidance
  • Supports various Android app frameworks (native, React Native, Flutter, Cordova)

Anwendungsfälle

  • Audit Android applications for Firebase misconfigurations
  • Test Firebase endpoints extracted from APKs
  • Assess mobile app security involving Firebase backends
  • Perform authorized penetration testing of Firebase-backed applications

Nicht-Ziele

  • Scanning apps without explicit authorization
  • Testing production Firebase projects without written permission
  • Extracting Firebase config without testing
  • Analyzing non-Android targets (iOS, web apps)

Scope

  • info:Dry-run previewThe README mentions a `--no-cleanup` option, which provides some control over modifications, but a full `--dry-run` mode for previewing intended actions is not explicitly documented.

Installation

Zuerst Marketplace hinzufügen

/plugin marketplace add trailofbits/skills
/plugin install firebase-apk-scanner@trailofbits

Qualitätspunktzahl

Verifiziert
98 /100
Analysiert about 17 hours ago

Vertrauenssignale

Letzter Commit3 days ago
Sterne5.2k
LizenzCC-BY-SA-4.0
Status
Quellcode ansehen