T09 · Insecure Skill Coding Practices
- Location
login.py:36- Finding
Sensitive login credentials exposed through command-line arguments
- Content
View full analysis
") sys.exit(1) mobile = sys.argv[1] code = sys.argv[2] qinglite_login(mobile, code) ``` ### Technical Analysis The script requires the user's mobile number and one-time verification code to be supplied as command-line arguments. Command-line arguments may be exposed through process inspection facilities, shell history, terminal-session recording, CI logs, audit systems, and orchestration metadata. Although sending these values to the documented Qinglite login endpoint is necessary for the declared login operation, exposing them through the command line is not necessary and exceeds secure minimum handling requirements. A verification code should be treated as an authentication secret during its validity period. ### Attack Path 1. A victim invokes `login.py` with a mobile number and valid verification code. 2. The arguments are recorded in shell history, captured by execution logging, or observed through local process inspection while the command is running. 3. A local user, monitoring operator, or log reader obtains the mobile number and code. 4. If the code remains valid, the attacker submits it to the Qinglite login endpoint. 5. The attacker may obtain an authenticated token for the victim's account. ### Impact Assessment Successful exploitation may disclose personally identifiable information and a temporary authentication factor. If the verification code is still valid and accepted by the service, an attacker may authenticate as the victim and obtain the account token. The resulting access is limited by the permissions granted to that token, including the documented ability to publish Qinglite content. ]]>- Remediation
View remediation
