T09 · Insecure Skill Coding Practices
- Location
ip.py:8- Finding
API Credential and Query Data Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
ip.py, lines 8–26
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: HighVulnerable Code
python API_URL = "http://apis.juhe.cn/ip/ipNewV3" API_KEY = os.getenv("JUHE_API_KEY", "").strip() def query_ip(ip): params = { "ip": ip, "key": API_KEY } headers = { "Content-Type": "application/x-www-form-urlencoded" } try: resp = requests.get(API_URL, params=params, headers=headers, timeout=10)Technical Analysis
The application sends the Juhe API credential and the queried IP address to a plaintext HTTP endpoint. Because
requests.get()encodesparamsinto the URL query string, the resulting request includes both sensitive values in a URL similar to:text http://apis.juhe.cn/ip/ipNewV3?ip=114.114.114.114&key=API_KEYPlaintext HTTP provides neither transport confidentiality nor server authentication. An attacker with visibility or control over the network path can read the credential, inspect queried IP addresses, modify requests, or forge API responses. A server-side redirect to HTTPS would not resolve the issue because the initial HTTP request already discloses the query string.
Query-string credentials may also be retained by HTTP proxies, gateways, monitoring systems, and access logs.
Attack Path
- A user configures a valid
JUHE_API_KEYand invokes the Skill. - The Skill constructs a plaintext HTTP request whose query string contains the API key and target IP address.
- An attacker positioned on the local network, an untrusted wireless network, a compromised proxy, or another network transit point observes or intercepts the request.
- The attacker extracts and reuses the API credential, or modifies the request or response in transit.
- Reused credentials can consume the victim's API quota, while a modified response can cause ...[truncated 607 chars]
- A user configures a valid
- Remediation
View remediation
Remediation Suggestions
- Replace the endpoint with the API provider's verified HTTPS endpoint:
python API_URL = "https://apis.juhe.cn/ip/ipNewV3" - Confirm from the provider's official documentation that this endpoint supports TLS and validate its certificate normally.
- Disable or explicitly reject redirects from HTTPS to HTTP.
- Where supported by the provider, transmit the credential through an authorization header rather than a URL query parameter.
- If query-string authentication is mandatory, ensure all requests use HTTPS and configure application, proxy, and gateway logging to redact the
keyparameter. - Rotate the current API key if this code has been used over an untrusted network.
- Add an automated test that rejects any API endpoint whose URL scheme is not
https.
- Replace the endpoint with the API provider's verified HTTPS endpoint:
