T09 · Insecure Skill Coding Practices
- Location
scripts/check_site.sh:8- Finding
Unrestricted Network Targets Enable Server-Side Request Forgery and Internal Service Probing
- Content
View full analysis
}" # Ensure URL has scheme if [[ ! "$URL" =~ ^https?:// ]]; then URL="https://$URL" fi # Create temp file for headers HEADER_FILE=$(mktemp) trap 'rm -f "$HEADER_FILE"' EXIT # Perform the request with timing HTTP_CODE=$(curl -s -o /dev/null -w '%{json}' \ --max-time 15 \ --connect-timeout 10 \ -D "$HEADER_FILE" \ -L \ "$URL" 2>/dev/null) || { echo "{\"url\":\"$URL\",\"status\":\"error\",\"status_code\":0,\"error\":\"Connection failed or timed out\",\"timestamp\":\"$(date -u +%Y-%m-%dT%H:%M:%SZ)\"}" exit 0 } ``` From `scripts/check_ssl.sh`: ```bash DOMAIN="${1:?Usage: check_ssl.sh }" # Strip protocol and path if provided DOMAIN=$(echo "$DOMAIN" | sed -E 's|^https?://||' | sed 's|/.*||' | sed 's|:.*||') # Get certificate info CERT_INFO=$(echo | openssl s_client -servername "$DOMAIN" -connect "$DOMAIN:443" 2>/dev/null) || { echo "{\"domain\":\"$DOMAIN\",\"status\":\"error\",\"error\":\"Could not connect to $DOMAIN:443\",\"timestamp\":\"$(date -u +%Y-%m-%dT%H:%M:%SZ)\"}" exit 0 } ``` ### Technical Analysis Both scripts accept an arbitrary destination without checking whether the resolved address is public. They do not reject loopback, private, link-local, reserved, multicast, or cloud-metadata address ranges. The HTTP implementation additionally uses `curl -L`, which follows redirects. Consequently, validating only the initial URL would still be insufficient: a public attacker-controlled endpoint could redirect the request to an internal address. The HTTP response body is discarded, which limits direct data extraction. However, the script still discloses response status, timing, redirect information, eff ...[truncated 1684 chars]- Remediation
View remediation
