fsp scans an APK and checks the Firestore database for rules that are not secure, testing with or without authentication.

If there are problems with the security rules, attackers could steal, modify or delete data and raise the bill.

Install fsp
sudo wget -O /bin/fsp
sudo chmod +x /bin/fsp

Running fsp

Scanning an APK without authentication
fsp app.apk
Scanning an APK with authentication

With email and password.

fsp app.apk

With a token.

fsp app.apk eyJhbGciO...

Download FireStorePwn


This is only an educational purposes only I am not responsible for further activities

Join my forum and learn more ethical hacking and penetration testing

Get me at


Leave a Reply

Your email address will not be published. Required fields are marked *