Это видео недоступно.
Сожалеем об этом.

Android Firebase Database takeover vulnerability | Bug bounty poc

Поделиться
HTML-код
  • Опубликовано: 27 мар 2024
  • In this video i am going to show you how to find vulnerability in android firebase database this is only for education so that everyone can hunt for this vulnerability and report to bounty program and secure there websites if anyone from youtube review team watching this please dont restrict this video it take times to find this vulnerability and teach everyone...
    Disclaimer: This video is for strictly educational and informational purpose only. I own all equipment used for this demonstration. Hacking without permission is illegal so always ensure you have proper authorization before using security tools in any network environment. thanks.

Комментарии • 168

  • @P3ntest3r
    @P3ntest3r 4 месяца назад +27

    Never give up even u get duplicate/rejection to ur bug bounty report be strong do it again u will win one day God Bless all Viewers u will get bug Bounty reward $200+ 🎉🎉

    • @lostsecc
      @lostsecc  4 месяца назад +2

      ❤️

    • @xTwistCinema
      @xTwistCinema 4 месяца назад +1

      Exactly! Just got my first bounty yesterday. Prototype poisoning chained to DOM XSS. Scored a high severity for my first bug :D This was the 5th bounty i'd tried in the day. All about persistence!

    • @lostsecc
      @lostsecc  4 месяца назад +1

      happy yo hear this ☺️

    • @P3ntest3r
      @P3ntest3r 4 месяца назад +1

      @@xTwistCinema congratulations bro i hope others will find too

    • @P3ntest3r
      @P3ntest3r 4 месяца назад +1

      @@lostsecc appreciate bro 🖐🖐😇😇

  • @Ajay_Yadav_Smart
    @Ajay_Yadav_Smart 4 месяца назад +8

    Literally I'm in love with your skills...❤❤❤

    • @lostsecc
      @lostsecc  4 месяца назад +1

      😇☺️❤️

  • @kochzzz
    @kochzzz 4 месяца назад +6

    best underrated channel

    • @lostsecc
      @lostsecc  4 месяца назад

      my pleasure to hear this ☺️😇

  • @shizlfazizl9578
    @shizlfazizl9578 4 месяца назад +2

    I really hope that the security specialist checking the POC is watching it with the same music. Thank you for your videos, you are inspiring

    • @lostsecc
      @lostsecc  4 месяца назад

      ☺️❤️yeahh if they watch it sure they like music 😉

  • @Souravsinghllb
    @Souravsinghllb 4 месяца назад +2

    Bro again, just love this tutorials ❤️

  • @1733-e7s
    @1733-e7s 4 месяца назад +2

    WOW What a data breach hats off bro

  • @harshh25.02
    @harshh25.02 4 месяца назад +2

    pls share your wsl theme. and also pls make video of all tools, scripts, extensions you use for hunt. Video is on fire 🔥🔥🔥🔥

    • @lostsecc
      @lostsecc  4 месяца назад

      join.telegram.i.will share there t.me/lostsec

  • @CyberxploitHausa
    @CyberxploitHausa 4 месяца назад +1

    Cool to have TopG in the intro bg music

  • @DavidJosh-pb1zp
    @DavidJosh-pb1zp 4 месяца назад

    I don't like the empty theories and repeated knowledge of other vloggers. I appreciate your training through practical and direct practice, for the first time since using RUclips. I have learned many practical and highly applicable things through your videos. Will donate to your positive and meaningful work

    • @lostsecc
      @lostsecc  4 месяца назад

      keep going brother always for you all 😇❤️

  • @Kiranrvc
    @Kiranrvc 4 месяца назад +2

    Thnx bro i installed successfully ❤️

  • @tomdotsh
    @tomdotsh 4 месяца назад +1

    Great video as always, have a great day brother

    • @lostsecc
      @lostsecc  4 месяца назад

      thnq brother 😇❤️

  • @aanyt5755
    @aanyt5755 4 месяца назад +2

    These man is born for make a history 👨‍💻 bug bounty industry

    • @lostsecc
      @lostsecc  4 месяца назад +1

      ☺️❤️😇

  • @Hacker_ankit_2025
    @Hacker_ankit_2025 4 месяца назад +1

    Bhai next video after you find a bug , aap usko kaise report karte ho ... For eg - mail kaise likhte ho , screenshot... Etc ... Please 🥺 make a video on this

  • @mr-dark
    @mr-dark 4 месяца назад +1

    This is very cool, keep it up brother ❤😊

    • @lostsecc
      @lostsecc  4 месяца назад

      thnq brother ❤️

  • @nonidentified89
    @nonidentified89 4 месяца назад +3

    Bro you are absoulute legend 💯💪

    • @lostsecc
      @lostsecc  4 месяца назад +1

      ❤️😇

  • @user-cc4zb3sx8j
    @user-cc4zb3sx8j 4 месяца назад +1

    Hi, I was wondering how you set the terminal background?
    P.S Amazing video!!

    • @lostsecc
      @lostsecc  4 месяца назад

      its wsl2 kali with ohmyposh custom theme

    • @user-cc4zb3sx8j
      @user-cc4zb3sx8j 4 месяца назад

      @@lostsecc Thank you for help!!

  • @kirtimanmohanty7575
    @kirtimanmohanty7575 3 месяца назад +1

    Bro i am a big fan of yours. Bro can you tell me how u find private programs for hunt

    • @lostsecc
      @lostsecc  3 месяца назад

      you need 2-4 valid p3 bug reports so you get invites..

    • @kirtimanmohanty7575
      @kirtimanmohanty7575 3 месяца назад

      Thank you bro

  • @musicdarija
    @musicdarija 4 месяца назад +1

    My friend have a problem I want you to help me You are the best person on RUclips legend

    • @lostsecc
      @lostsecc  4 месяца назад

      sure bro dm me in telegram @lostsec

    • @musicdarija
      @musicdarija 4 месяца назад

      bro do you have insta @@lostsecc

  • @exploitable0x1
    @exploitable0x1 4 месяца назад +1

    Nice catch

  • @Byrus_dsp
    @Byrus_dsp 4 месяца назад

    Nice POC .

    • @lostsecc
      @lostsecc  4 месяца назад +1

      thnq brother ❤️

  • @user-fp7fs9xl2t
    @user-fp7fs9xl2t 4 месяца назад +1

    love your content 🎉

  • @Dom-zy1qy
    @Dom-zy1qy 4 месяца назад +1

    Lmao, firebase Realtime db rules seem to have pretty bad docs (at least I couldn't get them working how i wanted when i used it), so people just end up using really insecure rules. (I was one of those people).
    Do you actually make money off of this tho? Is this actually part of a bug bounty program? Do you make decent money from doing bounties?

    • @lostsecc
      @lostsecc  4 месяца назад

      it cost 5000$+ if you find it in bug bounty program bro

  • @ohmarrr
    @ohmarrr 3 месяца назад

    play ken carson in the background this is so tuff

  • @drake_rl
    @drake_rl 4 месяца назад +1

    sorry for the question but I'm new to this, what can an attacker do with this?

    • @lostsecc
      @lostsecc  4 месяца назад

      you can read write all things in there firebase database

  • @IllIIIIIIllll
    @IllIIIIIIllll 4 месяца назад +1

    Bro do you also bug hunt in Android apps(ssl pinning bypass )or only websites?

    • @lostsecc
      @lostsecc  4 месяца назад

      there are many tool and software for testing it without ssl pinning bypass

    • @anderjones1547
      @anderjones1547 4 месяца назад

      @@lostsecc which one?

  • @testing5967
    @testing5967 4 месяца назад +1

    Bro, i want to buy your premium course.
    Please make course from beginning to advance in special bug bounty
    Please 🙏🏻🥺
    Please sir 😢 please
    I humble request
    Please sir 😢

    • @lostsecc
      @lostsecc  4 месяца назад

      you dont need to pay anything i will post free all things...just active on my telegram channel ❤️

  • @RAS02023
    @RAS02023 4 месяца назад

    🔥

  • @Kmax21
    @Kmax21 4 месяца назад +1

    It can be easily Avoided Right?

    • @lostsecc
      @lostsecc  4 месяца назад

      what

    • @Kmax21
      @Kmax21 4 месяца назад

      @@lostsecc no I mean website owners can avoid that by one click 🤧

    • @lostsecc
      @lostsecc  4 месяца назад

      depend on there brand

  • @krishnajoshi8643
    @krishnajoshi8643 4 месяца назад

    great work bro keep it up

  • @EinzzCookie
    @EinzzCookie 4 месяца назад +2

    How have you found the link to the database?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      decompile apk

    • @H4cker_Nafeed
      @H4cker_Nafeed 4 месяца назад

      ​@@lostsecc what is that ?

    • @lostsecc
      @lostsecc  4 месяца назад

      its android testing reverse engneering

  • @Hacker_ankit_2025
    @Hacker_ankit_2025 4 месяца назад +1

    Bhai mein aapke steps same to same follow karta hu fir bhi bugs nhi milte

    • @lostsecc
      @lostsecc  4 месяца назад

      try hard work sure u will do not a hard..

  • @mdalifislam7319
    @mdalifislam7319 4 месяца назад +1

    Wow 🎉

  • @mountainsoflavainc
    @mountainsoflavainc 4 месяца назад +1

    How did ya get a background on your wsl?

    • @lostsecc
      @lostsecc  4 месяца назад

      download window terminal from microsoft store

  • @Hacker_ankit_2025
    @Hacker_ankit_2025 4 месяца назад +1

    Bhai how did you find this api parameter to be vulnerable 🎉🎉

    • @lostsecc
      @lostsecc  4 месяца назад

      after decompile apk

  • @I_imperium
    @I_imperium 4 месяца назад +1

    Woohu

  • @ism1
    @ism1 4 месяца назад

    Can you explain from scratch until professionalism

    • @lostsecc
      @lostsecc  4 месяца назад +2

      youtube not allowed full touturials so i will send in my telegram channel.

  • @user-dw9dz4if5h
    @user-dw9dz4if5h 4 месяца назад +1

    AYYY GG

  • @xinbizz96
    @xinbizz96 4 месяца назад

    great job... teach me bro

  • @Kiranrvc
    @Kiranrvc 4 месяца назад

    Bro make a list of basic commands that you use for Bounty that can help lot bro

    • @lostsecc
      @lostsecc  4 месяца назад +1

      sure

    • @Kiranrvc
      @Kiranrvc 4 месяца назад

      ​@@lostseccthnk bro❤

  • @mr-dark
    @mr-dark 4 месяца назад +1

    ❤🎉

  • @mnageh-bo1mm
    @mnageh-bo1mm 4 месяца назад

    duddde the bug is still not fixed !? where did you get that 5000$ from ? they don't even have a bug bounty program

    • @lostsecc
      @lostsecc  4 месяца назад

      i said its worth 5000$ even more

    • @mnageh-bo1mm
      @mnageh-bo1mm 4 месяца назад

      ​@@lostsecc how ? you didn't get paid for it :

  • @abdul-azeez-v
    @abdul-azeez-v 4 месяца назад

    How did you find the firebase uri ??

    • @lostsecc
      @lostsecc  4 месяца назад

      decompile apk reverse engnerring

  • @user-mk3zz8zn9b
    @user-mk3zz8zn9b 4 месяца назад +1

    I see, this isnt a bug bounty program right?

    • @lostsecc
      @lostsecc  4 месяца назад

      yes,otherwise it not allowd in yt

  • @0RIPPER0
    @0RIPPER0 4 месяца назад +1

    Seeeeeeeeeeeeeeeeeeeeeeeeeesh...!

  • @H4cker_Nafeed
    @H4cker_Nafeed 4 месяца назад

    I get all bugs rejected or duplicate or p5

    • @lostsecc
      @lostsecc  4 месяца назад

      dont worry we all get in start keep going bro it takes time ...

  • @whateveritis0
    @whateveritis0 4 месяца назад

    How u found the firebase link and the endpoint

    • @lostsecc
      @lostsecc  4 месяца назад

      decompile apk

  • @The_ancestor_of_Mars_humans
    @The_ancestor_of_Mars_humans 4 месяца назад

    they don't have bug bounty program tho ??

    • @lostsecc
      @lostsecc  4 месяца назад

      no they are nigerian startup company

  • @Decoder__2770
    @Decoder__2770 4 месяца назад +1

    bro which operating system
    you use ??

    • @lostsecc
      @lostsecc  4 месяца назад +1

      kali wsl2

    • @Decoder__2770
      @Decoder__2770 4 месяца назад

      @@lostsecc please make a vedio how to setup in windows

    • @lostsecc
      @lostsecc  4 месяца назад

      ok

    • @Decoder__2770
      @Decoder__2770 4 месяца назад

      @@lostsecc thnkyou bhai

  • @kyou5786
    @kyou5786 4 месяца назад

    juicy

  • @egg.egg.egg.egg.
    @egg.egg.egg.egg. 4 месяца назад

    how much did you earn this year?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      this year i earned love and respect ❤️ that cost more then anything..

  • @AEGIS-RED-MEGA-VIEWS
    @AEGIS-RED-MEGA-VIEWS 4 месяца назад +1

    tate for president hacker

  • @radhesearch
    @radhesearch 4 месяца назад

    Brother i want to learn from you pls

    • @lostsecc
      @lostsecc  4 месяца назад

      join telegram @lostsec

  • @abhishekkumar_981
    @abhishekkumar_981 4 месяца назад +1

    Hey how to start mobile pentesting

    • @I_imperium
      @I_imperium 4 месяца назад

      Termux

    • @lostsecc
      @lostsecc  4 месяца назад

      🤣not termux bro

    • @lostsecc
      @lostsecc  4 месяца назад +1

      just decompile the apk and find sensitive firebase endpoint ..

    • @I_imperium
      @I_imperium 4 месяца назад

      @@lostsecc oh I have seen somewhere penetration testing using termux.
      There's tool on ps called termux tools & commands. That's where I learned
      Anyway I got it👌

    • @compbums4270
      @compbums4270 4 месяца назад

      @@lostsecc what tools are you using to decompile the apk?

  • @ajaychoudhary7666
    @ajaychoudhary7666 4 месяца назад +1

    How to find this vulnerability

    • @lostsecc
      @lostsecc  4 месяца назад

      you need to learn android testing..

    • @I_Unintentionally_Morph
      @I_Unintentionally_Morph 4 месяца назад

      ​@@lostseccplease can you make a video on important or necessary things one needs to know to start things.

    • @lostsecc
      @lostsecc  4 месяца назад

      sure

    • @ajaychoudhary7666
      @ajaychoudhary7666 4 месяца назад

      I can remove client side security in general but where did I get this link from

    • @ajaychoudhary7666
      @ajaychoudhary7666 4 месяца назад

      How to do remote code execution during application penetration

  • @ism1
    @ism1 4 месяца назад

    How do I find these files?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      you need to learn android testing

  • @mnsds1332
    @mnsds1332 4 месяца назад

    abi yalvarırım roadmap videosu paylaş

  • @ankitjha883
    @ankitjha883 4 месяца назад

    Is this private program or in hackerone

    • @lostsecc
      @lostsecc  4 месяца назад

      nope hackerone programs policy not allowed to show these much sensitive data its a wrkman app just search on playstore..

  • @monikasharma2931
    @monikasharma2931 4 месяца назад +1

    Amazing 😮❤

    • @lostsecc
      @lostsecc  4 месяца назад

      ☺️❤️

  • @sw4pn3h0x8
    @sw4pn3h0x8 4 месяца назад

    Bro did they paid you 5k$ for this?

    • @lostsecc
      @lostsecc  4 месяца назад

      they are newly started company in nigeria i talked with him he is fixing that issue...

  • @mnageh-bo1mm
    @mnageh-bo1mm 4 месяца назад

    how did you find it ?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      decompile apk

    • @mnageh-bo1mm
      @mnageh-bo1mm 4 месяца назад

      @@lostsecc and then how do i find that url?
      is there a script to do it en masse ?

    • @lostsecc
      @lostsecc  4 месяца назад

      you need to look in there storage database after decompile

    • @mnageh-bo1mm
      @mnageh-bo1mm 4 месяца назад

      @@lostsecc do a video about it

  • @mhm2217hunter
    @mhm2217hunter 4 месяца назад

    Bounty?? And Song name???

  • @user-ys6xt2zc6b
    @user-ys6xt2zc6b 4 месяца назад

    i think it got rejected

    • @lostsecc
      @lostsecc  4 месяца назад

      nope i have discussion with the company ceo in twitter it will fix soon..

    • @user-ys6xt2zc6b
      @user-ys6xt2zc6b 4 месяца назад

      @@lostsecc but they havent paid right?

    • @lostsecc
      @lostsecc  4 месяца назад

      they will pay after fix

  • @HackerFORgodwinn
    @HackerFORgodwinn 4 месяца назад

    Terminal name ?

    • @lostsecc
      @lostsecc  4 месяца назад +1

      kali wsl2 window terminal

  • @ghost_sec
    @ghost_sec 4 месяца назад

    bro, how many gaps have you found? how much money have you earned? 🤣

  • @Kiranrvc
    @Kiranrvc 4 месяца назад

    Bro anew tool is not installing in kali linux how can i install it

    • @lostsecc
      @lostsecc  4 месяца назад

      dm me in telegram what the error u facing..

    • @Kiranrvc
      @Kiranrvc 4 месяца назад

      Bro i contacted the bot but no response came bro​@@lostsecc

    • @lostsecc
      @lostsecc  4 месяца назад

      what is.your name is telegram

    • @Kiranrvc
      @Kiranrvc 4 месяца назад

      Kiran bro