{"id":37113630,"url":"https://github.com/jacobdavidalcock/firescan","last_synced_at":"2026-01-14T13:24:10.827Z","repository":{"id":304005331,"uuid":"1017464769","full_name":"JacobDavidAlcock/firescan","owner":"JacobDavidAlcock","description":"A comprehensive Firebase security auditing tool with an interactive console.","archived":false,"fork":false,"pushed_at":"2025-11-29T16:47:54.000Z","size":49667,"stargazers_count":49,"open_issues_count":0,"forks_count":3,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-12-01T19:47:39.560Z","etag":null,"topics":["firebase","firebase-auth","firebase-firestore","firebase-pentest","firebase-testing","firestore","pentesting"],"latest_commit_sha":null,"homepage":"https://firescan.jacobalcock.co.uk","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/JacobDavidAlcock.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-07-10T15:14:44.000Z","updated_at":"2025-11-30T20:14:41.000Z","dependencies_parsed_at":"2025-07-10T22:01:42.880Z","dependency_job_id":"af55f1d9-2993-482d-ab78-d2dcdf28609a","html_url":"https://github.com/JacobDavidAlcock/firescan","commit_stats":null,"previous_names":["jacobdavidalcock/firescan"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/JacobDavidAlcock/firescan","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JacobDavidAlcock%2Ffirescan","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JacobDavidAlcock%2Ffirescan/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JacobDavidAlcock%2Ffirescan/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JacobDavidAlcock%2Ffirescan/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/JacobDavidAlcock","download_url":"https://codeload.github.com/JacobDavidAlcock/firescan/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/JacobDavidAlcock%2Ffirescan/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28421148,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T10:47:48.104Z","status":"ssl_error","status_checked_at":"2026-01-14T10:46:19.031Z","response_time":107,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["firebase","firebase-auth","firebase-firestore","firebase-pentest","firebase-testing","firestore","pentesting"],"created_at":"2026-01-14T13:24:10.343Z","updated_at":"2026-01-14T13:24:10.814Z","avatar_url":"https://github.com/JacobDavidAlcock.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n\u003cpre\u003e\n███████╗██╗██████╗ ███████╗███████╗ ██████╗ █████╗ ███╗   ██╗\n██╔════╝██║██╔══██╗██╔════╝██╔════╝██╔════╝██╔══██╗████╗  ██║\n█████╗  ██║██████╔╝█████╗  ███████╗██║     ███████║██╔██╗ ██║\n██╔══╝  ██║██╔══██╗██╔══╝  ╚════██║██║     ██╔══██║██║╚██╗██║\n██║     ██║██║  ██║███████╗███████║╚██████╗██║  ██║██║ ╚████║\n╚═╝     ╚═╝╚═╝  ╚═╝╚══════╝╚══════╝ ╚═════╝╚═╝  ╚═╝╚═╝  ╚═══╝\n\u003c/pre\u003e\n\n# FireScan\n\n**Automated security testing for Firebase applications**\n\n[![Release](https://img.shields.io/github/v/release/JacobDavidAlcock/firescan)](https://github.com/JacobDavidAlcock/firescan/releases)\n[![License](https://img.shields.io/github/license/JacobDavidAlcock/firescan)](LICENSE)\n[![Go Version](https://img.shields.io/github/go-mod/go-version/JacobDavidAlcock/firescan)](go.mod)\n[![Build Status](https://github.com/JacobDavidAlcock/firescan/workflows/Test/badge.svg)](https://github.com/JacobDavidAlcock/firescan/actions)\n[![Go Report Card](https://goreportcard.com/badge/github.com/JacobDavidAlcock/firescan)](https://goreportcard.com/report/github.com/JacobDavidAlcock/firescan)\n\n\u003cimg src=\"demo.gif\" alt=\"FireScan Demo\" width=\"800px\"\u003e\n\n\u003c/div\u003e\n\n## Overview\n\nInteractive security auditing tool for Firebase. Automatically enumerates and tests Realtime Database, Firestore, Cloud Storage, Cloud Functions, and Authentication.\n\n**Features:**\n- Interactive console with command history\n- Concurrent scanning (1-1000 workers)\n- Automatic JWT refresh\n- Built-in wordlists with case variations\n- Three safety modes: probe (read-only), test (safe writes), audit (deep testing)\n- JSON output\n\n## Quick Start\n\n**Install:**\n```bash\n# Using Go\ngo install github.com/JacobDavidAlcock/firescan/cmd/firescan@latest\n\n# Or download binary\nhttps://github.com/JacobDavidAlcock/firescan/releases/latest\n```\n\n**Usage:**\n```bash\nfirescan\n\u003e set projectID your-firebase-app\n\u003e set apiKey AIzaSy...\n\u003e auth --create-account\n\u003e scan --all\n```\n\n## Commands\n\n**Authentication:**\n```bash\nauth --create-account              # Create test account\nauth -e user@email.com -P pass     # Login with credentials\nauth --enum-providers              # Enumerate auth providers\nauth logout                        # Clear session\n```\n\n**Scanning:**\n```bash\nscan --all                         # Scan all services\nscan --rtdb --firestore            # Specific services\nscan --unauth                      # Test without authentication\nscan --all -c 100 --rate-limit 50  # 100 workers, 50 req/s\nscan --all --json                  # JSON output\n```\n\n**Data Extraction:**\n```bash\nextract --firestore --path users\nextract --rtdb --path /admin/config\nextract --firestore --path users --output data.json\n```\n\n**Wordlists:**\n```bash\nwordlist show                      # List available wordlists\nwordlist show users                # View wordlist contents\nwordlist add custom admin,secret   # Create custom wordlist\n```\n\nBuilt-in wordlists: `users`, `config`, `passwords`, `functions`, `database`, `storage`, `security`, `all`\n\n## Service Coverage\n\n| Service | Capabilities |\n|---------|-------------|\n| **Realtime Database** | Node enumeration, read access testing, root exposure detection |\n| **Firestore** | Collection discovery, document enumeration, permission testing |\n| **Cloud Storage** | Bucket listing, file enumeration, ACL testing |\n| **Cloud Functions** | Function discovery across 7 regions, auth validation |\n| **Authentication** | Automated provider enumeration, JWT testing, token validation |\n| **Hosting** | Sensitive file detection (.git, .env, config files) |\n\n## Safety Modes\n\n```\n🟢 PROBE (default)  → Read-only operations\n🟡 TEST             → Safe write tests with cleanup\n🔴 AUDIT            → Deep testing (requires confirmation)\n```\n\n## Installation\n\n**Linux:**\n```bash\ncurl -sL https://github.com/JacobDavidAlcock/firescan/releases/latest/download/firescan-linux-amd64.tar.gz | tar xz\nsudo mv firescan /usr/local/bin/\n```\n\n**macOS:**\n```bash\ncurl -sL https://github.com/JacobDavidAlcock/firescan/releases/latest/download/firescan-darwin-amd64.tar.gz | tar xz\nsudo mv firescan /usr/local/bin/\n```\n\n**Windows:**\nDownload from [releases](https://github.com/JacobDavidAlcock/firescan/releases/latest), extract, and add to PATH.\n\n**From Source:**\n```bash\ngit clone https://github.com/JacobDavidAlcock/firescan.git\ncd firescan\ngo build -o firescan cmd/firescan/main.go\n```\n\n## Examples\n\n**Penetration Testing:**\n```bash\n\u003e set projectID target-app\n\u003e auth --create-account\n\u003e scan --all --json \u003e findings.json\n```\n\n**Pre-deployment Check:**\n```bash\n\u003e scan --unauth\n\u003e scan --rules\n```\n\n**Bug Bounty:**\n```bash\n\u003e scan --all -c 100 --rate-limit 50\n\u003e extract --firestore --path users --output evidence.json\n```\n\n## Comparison\n\n| Feature | FireScan | Manual Testing | Firebase Emulator |\n|---------|----------|----------------|-------------------|\n| Speed | ~2 minutes | 20+ minutes | N/A |\n| Automation | Full | Manual | Partial |\n| Service Coverage | All services | All services | Limited |\n| Production Testing | ✅ Safe | ⚠️ Risky | ❌ Dev only |\n\n## Roadmap\n\n**Current (v2.1.0)**\n- Full service scanning (RTDB, Firestore, Storage, Functions, Auth, Hosting)\n- Enhanced Hosting scanner (sensitive file detection)\n- Automated Auth provider enumeration\n- CI/CD integration (non-interactive CLI mode)\n- Three safety modes\n- Session management and auto-refresh\n- Custom wordlists and JSON output\n\n**Next (v2.2.0)**\n- Cleanup implementation\n- HTML/PDF report generation\n- Enhanced error reporting\n\n**Planned (v3.0.0)**\n- Firebase rules analyzer\n- Multi-project scanning\n- Continuous monitoring mode\n\n## Legal\n\n⚠️ **FireScan is for authorized security testing only.** Unauthorized testing is illegal.\n\n## License\n\nMIT License - see [LICENSE](LICENSE)\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n**Made by [Jacob Alcock](https://jacobalcock.co.uk)**\n\n[Website](https://jacobalcock.co.uk) • [LinkedIn](https://www.linkedin.com/in/jacob-alcock/) • [Blog](https://blog.jacobalcock.co.uk)\n\n\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjacobdavidalcock%2Ffirescan","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjacobdavidalcock%2Ffirescan","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjacobdavidalcock%2Ffirescan/lists"}