T09 · Insecure Skill Coding Practices
- Location
ucap-sensitive-check-skill/main.py:327- Finding
Automatic Redirect Handling and DNS TOCTOU Permit SSRF
- Content
View full analysis
list: """ Convert a hostname into a list of IP addresses. """ results = [] if HAS_DNSPYTHON: for rtype in ("A", "AAAA"): try: answers = dns.resolver.resolve(hostname, rtype, lifetime=5) for rdata in answers: try: results.append(ipaddress.ip_address(str(rdata))) except ValueError: pass except Exception: pass else: try: infos = socket.getaddrinfo(hostname, None, socket.AF_UNSPEC, socket.SOCK_STREAM, 0, socket.AI_ADDRCONFIG) for info in infos: addr = info[4][0] try: results.append(ipaddress.ip_address(addr)) except ValueError: pass except Exception: pass return results ``` ```python response = requests.get(url, headers=headers, timeout=15, verify=True, allow_redirects=True) response.raise_for_status() # Validate again after redirects final_url = response.url if final_url != url: is_safe2, err2 = validate_url_security(final_url) if not is_safe2: return {"code": -100, "message": f"Page redirect security check failed: {err2}", "data": None} ``` ### Technical Analysis The initial URL is resolved and checked before the HTTP request. However, `requests.get()` is invoked with `allow_redirects=True`, so the library follows redirects before the final URL is validated. If a public HTTPS endpoint returns a redirect to a priv ...[truncated 2055 chars]- Remediation
View remediation
