T09 · Insecure Skill Coding Practices
- Location
scripts/monitor_v2.py:330- Finding
Unauthenticated HTTP Transport for Technical Market Data
- Content
View full analysis
= 20: self._mark_source_success(source_name) return klines, None ``` ### Technical Analysis The 10jqka fallback endpoint uses plaintext HTTP. HTTP provides neither server authentication nor transport integrity, allowing a network-positioned attacker to observe and modify the response. The returned JSONP content is parsed as trusted market data and passed to `calculate_indicators()`. That method calculates moving averages, RSI, volume ratios, golden crosses, and death crosses. These values are then used to produce user-facing financial alerts. The implementation does not authenticate the response, verify its origin, enforce HTTPS, or cross-check fallback data against an independent source. It also does not call `raise_for_status()` before parsing the response. ### Attack Path 1. The preferred Eastmoney source fails or becomes unavailable. 2. The application falls back to the plaintext 10jqka endpoint. 3. An attacker with control over a network gateway, local wireless network, DNS path, or upstream proxy intercepts the HTTP request. 4. The attacker returns syntactically valid JSONP containing fabricated closing prices or volume data. 5. The application accept ...[truncated 931 chars]- Remediation
View remediation
