T09 · Insecure Skill Coding Practices
- Location
scripts/a_stock_market_review.py:21- Finding
Market data retrieved over unencrypted HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/a_stock_market_review.py, line 21
Vulnerability Type: Unencrypted external API communication
Risk Level: MediumVulnerable Code:
python BASE_URL = "http://push2.eastmoney.com/api/qt"Technical Analysis
All market-data requests are constructed from a plaintext HTTP base URL. HTTP provides neither server authentication nor transport integrity. An attacker with a network interception position can observe requests, impersonate the API endpoint, modify JSON responses, or redirect traffic.
The application parses the received JSON without cryptographic verification and incorporates its values directly into the generated financial report. While no remote response is executed as code and no credentials are transmitted, forged prices, percentage changes, sector rankings, or stock selections could be presented as legitimate market information.
Attack Path
- A user runs the market-review script on a network controlled or observed by an attacker.
- The script sends requests to
http://push2.eastmoney.com/api/qt/.... - The attacker intercepts the plaintext HTTP connection through a malicious access point, compromised router, proxy, or equivalent man-in-the-middle position.
- The attacker returns syntactically valid but manipulated Eastmoney JSON data.
- The
_getmethod accepts and parses the response. - The modified figures are inserted into the report and displayed to the user as market data.
Impact Assessment
This issue does not grant the attacker local code execution, filesystem access, elevated privileges, or persistence. Its scope is limited primarily to the confidentiality and integrity of API traffic and the resulting report. However, manipulated financial information could mislead users and influence investment-related analysis or decisions.
- Remediation
View remediation
Remediation Suggestions
-
Replace the base URL with the HTTPS endpoint:
python BASE_URL = "https://push2.eastmoney.com/api/qt" -
Keep TLS certificate verification enabled; do not use
verify=False. -
Restrict redirects or verify that the final response host remains an approved Eastmoney domain.
-
Validate the response content type, expected schema, and reasonable numeric ranges before using returned values.
-
Fail closed when transport validation or response validation fails rather than presenting untrusted values as valid market data.
-
