T09 · Insecure Skill Coding Practices
- Location
send_email.py:59- Finding
SMTP TLS connections do not explicitly enforce certificate verification
- Content
View full analysis
Vulnerability Details
File Location:
send_email.py, lines 59–64
Vulnerability Type: Improper TLS certificate validation
Risk Level: Mediumpython # 连接SMTP服务器并发送 if USE_TLS: server = smtplib.SMTP(SMTP_SERVER, SMTP_PORT) server.starttls() else: server = smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT)Technical Analysis
Both SMTP connection modes rely on the Python runtime's implicit SSL context. The implementation does not create an explicitly certificate-verifying
SSLContextor pass one toSMTP_SSLandstarttls.Because the resulting certificate-validation behavior can depend on the Python version and runtime configuration, the code does not reliably guarantee that the SMTP endpoint's certificate and hostname will be authenticated before credentials are submitted. The connection also lacks an explicit timeout.
Attack Path
- An attacker gains a position capable of manipulating DNS resolution or intercepting traffic between the host and the configured SMTP server.
- The attacker redirects the SMTP connection to a fraudulent endpoint.
- In a runtime where the implicit context does not adequately validate the certificate and hostname, the connection succeeds.
- The script calls
server.login(SENDER_EMAIL, AUTHORIZATION_CODE). - The fraudulent endpoint receives the SMTP account identifier and authorization code. Email content and attachments sent through that connection may also be disclosed.
Impact Assessment
Successful exploitation does not directly grant local operating-system privileges. It can disclose the configured SMTP credentials, potentially allowing the attacker to send email as the compromised account within the provider's authorization scope. Message bodies, recipient addresses, subjects, and attached local files may also be exposed in transit.
- Remediation
View remediation
Remediation Suggestions
Create a certificate-verifying context with
ssl.create_default_context()and use it for both connection modes:python import ssl tls_context = ssl.create_default_context() if USE_TLS: server = smtplib.SMTP(SMTP_SERVER, SMTP_PORT, timeout=30) server.ehlo() server.starttls(context=tls_context) server.ehlo() else: server = smtplib.SMTP_SSL( SMTP_SERVER, SMTP_PORT, timeout=30, context=tls_context, )Do not disable hostname checks or use an unverified SSL context. Require TLS before authentication, reject plaintext SMTP configurations, add a finite network timeout, and use a context manager or
finallyblock to ensure the connection is closed on failure.
