T09 · Insecure Skill Coding Practices
- Location
scripts/simtrade_core/market_data.py:72- Finding
Unauthenticated HTTP Order-Book Data Can Manipulate Simulated Trade Execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/simtrade_core/market_data.py:72-76
Vulnerability Type: Unauthenticated plaintext transport for execution-critical market data
Risk Level: Mediumpython response = requests.get( f"http://hq.sinajs.cn/list={symbol}", headers={"Referer": "http://finance.sina.com.cn"}, timeout=5, )The affected request is used by the Sina fallback to obtain a five-level order book. That order book can subsequently determine simulated fill prices and quantities.
Technical Analysis
The fallback obtains market data over plaintext HTTP, which provides neither server authentication nor transport integrity. An attacker capable of intercepting or modifying network traffic can therefore alter the response.
The implementation compares Sina data with East Money using the security name, previous close, timestamp, and last price. However, it does not authenticate or independently compare the bid and ask levels. The schema validation only establishes that each order-book level has a positive price and quantity and that no side contains more than five levels.
The accepted bid and ask levels are consumed by the matching engine in
scripts/simtrade_core/service.py:388-402, where they directly determine executable prices and fill quantities. Consequently, the cross-provider checks do not prevent a response from preserving validated metadata while supplying manipulated order-book levels.Attack Path
- East Money reports a normal trading security but omits its order book, causing the Sina fallback to execute.
- An on-path attacker intercepts the plaintext request to
hq.sinajs.cn. - The attacker returns a syntactically valid response containing the expected symbol, security name, previous close, a current timestamp, and a last price within the permitted tolerance.
- The attacker substitutes chosen bid or ask prices and quantities that still satisfy the basic po ...[truncated 814 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the plaintext endpoint with an HTTPS endpoint that performs standard certificate and hostname verification.
- If Sina cannot provide authenticated transport, remove this fallback from execution-critical workflows and fail closed when East Money lacks an order book.
- Alternatively, obtain bid and ask levels from another independently authenticated provider and require cross-provider consistency before matching.
- Validate that bid and ask levels are correctly ordered, do not form an invalid spread, remain within authenticated daily price limits, and are reasonably consistent with the authenticated last price.
- Keep metadata comparison, but extend integrity checks to every execution-critical field, particularly order-book prices and quantities.
- Add tests that inject a response with valid metadata but manipulated book levels and verify that matching is rejected.
