T09 · Insecure Skill Coding Practices
- Location
scripts/fofa_search_cli.py:68- Finding
Arbitrary API Base URL Can Expose FOFA Credentials and Search Queries
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fofa_search_cli.py, lines 68–79; related argument flow at lines 218 and 259
Vulnerability Type: Unrestricted credential-bearing network destination
Risk Level: HighVulnerable Code
python self.base_url = base_url.rstrip("/") self.timeout = timeout self.session = requests.Session() self.lang = "zh-CN" if get_shell_language().startswith("zh") else "en" if not self.key: raise FofaError("FOFA key is empty") def _request(self, path: str, params: Optional[Dict] = None, retries: int = 3) -> Dict: url = f"{self.base_url}{path}" request_params = dict(params or {}) request_params["key"] = self.key request_params["lang"] = self.langThe unrestricted destination is exposed through the command-line interface and passed directly to the client:
python parser.add_argument("--base-url", default=DEFAULT_BASE_URL, help=f"fofa base url, default: {DEFAULT_BASE_URL}")python client = FofaClient(key=args.key, base_url=args.base_url)The resulting request transmits the sensitive parameters to the selected destination:
python resp = self.session.get(url, params=request_params, timeout=self.timeout)Technical Analysis
The user-controlled
--base-urlvalue is accepted without validating its scheme or hostname. The client appends FOFA API paths to this value and includes the FOFA API key in every request's query parameters. The search query is also transmitted as theqbase64parameter bysearch()andsearch_next().Base64 encoding of the search query is expected by the FOFA API and is not encryption or, by itself, evidence of a covert channel. Nevertheless, an arbitrary server receiving
qbase64can trivially decode it. The sensitive-data transmission alert is therefore materially relevant because both the key and encoded query can be sent to any destination selected through--base-url....[truncated 1866 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
--base-urlif custom endpoints are not essential to the Skill's declared functionality. - If custom endpoints are required, parse the URL with
urllib.parse.urlparseand enforce:- The
httpsscheme. - An explicit allowlist of trusted FOFA hostnames.
- No embedded username or password.
- No unexpected port unless explicitly approved.
- The
- Reject loopback, link-local, private, and metadata-service addresses unless a documented deployment requirement specifically permits them.
- Disable automatic redirects or validate every redirect target before forwarding credentials:
python resp = self.session.get( url, params=request_params, timeout=self.timeout, allow_redirects=False, ) - Where supported by the FOFA API, transmit credentials in an authorization header rather than in URL query parameters. Ensure exception messages and logs do not contain authorization values.
- If compatibility requires several FOFA domains, expose a fixed environment or configuration allowlist rather than accepting arbitrary destinations at each invocation.
- Add tests confirming that HTTP URLs, unapproved domains, embedded credentials, and redirects to untrusted hosts are rejected before any key-bearing request is sent.
- Remove
