T09 · Insecure Skill Coding Practices
- Location
scripts/wechat_article.py:18- Finding
Hardcoded WeChat Authentication Session Credentials
- Content
View full analysis
Vulnerability Details
File Location:
scripts/wechat_article.py:18-21(credential declaration), with credential use atscripts/wechat_article.py:23-30,35-52,59-79, and97-101
Vulnerability Type: Hardcoded authentication credentials and plaintext sensitive data
Risk Level: HighVulnerable Code
The credential values below are redacted to prevent further disclosure. The source contains complete plaintext values for account and session-related cookie fields, including
wxuin,data_ticket,slave_sid,slave_user, andwxtokenkey.python def load_cookie(): """加载 Cookie""" cookie_str = """ua_id=REDACTED; wxuin=REDACTED; mm_lang=zh_CN; pac_uid=REDACTED; omgid=REDACTED; _qimei_uuid42=REDACTED; _qimei_fingerprint=REDACTED; _qimei_q36=; _qimei_h38=REDACTED; _clck=REDACTED; uuid=REDACTED; rand_info=REDACTED; slave_bizuin=REDACTED; data_bizuin=REDACTED; bizuin=REDACTED; data_ticket=REDACTED; slave_sid=REDACTED; slave_user=REDACTED; xid=REDACTED; _clsk=REDACTED; rewardsn=; wxtokenkey=777""" return cookie_strThe hardcoded credential is then used as the HTTP
Cookieheader:python def get_token(cookie): """获取 token""" headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36", "Cookie": cookie, "Referer": "https://mp.weixin.qq.com/" } r = requests.get("https://mp.weixin.qq.com/", headers=headers, allow_redirects=True) parsed = urlparse(r.url) params = parse_qs(parsed.query) return params.get('token', [None])[0]python cookie = load_cookie() # 获取 token print("🔑 获取 token...") token = get_token(cookie)Technical Analysis
The script embeds a complete authenticated WeChat session cookie directly in source code. Session fields such as
data_ticketandslave_sidare bearer-style credentials: possession may be sufficient to make requests under the authe ...[truncated 2276 chars]- Remediation
View remediation
Remediation Suggestions
- Immediately revoke all WeChat sessions associated with the exposed cookie and authenticate again to generate new credentials.
- Remove the cookie from the current source and all repository history, release archives, logs, caches, and deployed Skill copies.
- Replace
load_cookie()with logic that reads a user-owned secret from the documented configuration file or a secret-management facility. - Require restrictive file permissions, such as mode
0600, for any cookie file and reject files readable by other users where supported. - Do not provide a fallback credential. Fail closed with a clear error when no user-supplied cookie is configured.
- Avoid exposing cookie or token values in exceptions, debug output, telemetry, or logs.
- Add secret scanning to pre-commit and continuous-integration workflows to detect session cookies and similar credentials before release.
- Keep configuration documentation synchronized with implementation and document secure credential rotation and revocation procedures.
- Where supported by WeChat, use a narrowly scoped, revocable authentication mechanism rather than a full browser session cookie.
