T09 · Insecure Skill Coding Practices
- Location
scripts/dygod_crawler.py:531- Finding
Hard-Coded NAS Credentials Expose Privileged DownloadStation Access
- Content
View full analysis
Optional[str]: """Log in to Synology and obtain a SID.""" url = f"http://{SYNOLOGY_HOST}:{SYNOLOGY_PORT}/webapi/entry.cgi" params = { "api": "SYNO.API.Auth", "version": 6, "method": "login", "account": SYNOLOGY_USER, "passwd": SYNOLOGY_PASS, "session": session, "format": "sid" } try: resp = requests.get(url, params=params, timeout=10) data = resp.json() if data.get("success"): return data["data"]["sid"] except Exception as e: print(f"[Login failed] {e}") return None ``` The same credential is disclosed in the documentation: ```bash curl.exe -s "http://192.168.123.223:5000/webapi/entry.cgi?api=SYNO.API.Auth&version=6&method=login&account=xiaoai&passwd=Xx654321&session=DownloadStation&format=sid" ``` ### Technical Analysis A fixed NAS username, password, host address, and port are embedded directly in both executable source code and user-facing documentation. Anyone with access to the Skill package can recover the credentials without executing the application. The credentials are not installation placeholders: the script directly submits them to the Synology authentication API. Secret exposure is compounded by transmission over unencrypted HTTP and placement in URL query parameters. URLs may be retained in proxy logs, network appliance logs, debugging output, browser history, or monitoring systems. Embedding a reusable NAS credential exceeds the minimum privilege needed for movie lookup and crawling. Even for the declared optional download ...[truncated 1486 chars]- Remediation
View remediation
