T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:26- Finding
Unbounded Environment-Based Endpoint Discovery Enables Internal Network Probing
- Content
View full analysis
/dev/null | head -5) for port in $PORTS; do ENDPOINTS="$ENDPOINTS http://localhost:$port/health http://localhost:$port/healthz" done fi # From kubernetes rg -o "readinessProbe:.*path:\s*(\S+)" -g '*.yaml' -g '*.yml' 2>/dev/null | head -5 # Check each endpoint for endpoint in $ENDPOINTS; do RESPONSE=$(curl -s -o /tmp/health_body -w "%{http_code} %{time_total}s" --connect-timeout 5 --max-time 10 "$endpoint" 2>/dev/null) HTTP_CODE=$(echo "$RESPONSE" | awk '{print $1}') TIME=$(echo "$RESPONSE" | awk '{print $2}') if [ "$HTTP_CODE" = "200" ]; then echo "✅ $endpoint → $HTTP_CODE (${TIME})" elif [ "$HTTP_CODE" = "000" ]; then echo "❌ $endpoint → UNREACHABLE" else echo "⚠️ $endpoint → $HTTP_CODE (${TIME})" cat /tmp/health_body 2>/dev/null | head -3 fi done ``` ### Technical Analysis The Skill scans the complete process environment for variable values associated with broad names such as `URL`, `HOST`, `ENDPOINT`, or `SERVICE`. Every HTTP or HTTPS value discovered this way is automatically converted into four request targets and contacted using the network permissions of the process running the Skill. This behavior is not constrained to the deployment under verification. Environment variables may identify unrelated internal APIs, administrative interfaces, third-party servi ...[truncated 2105 chars]- Remediation
View remediation
