T09 · Insecure Skill Coding Practices
- Location
scripts/blackswan_monitor.py:26- Finding
Hardcoded Reusable SMTP Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/blackswan_monitor.py:26-32, with duplicate credentials infixed_monitor.py:20-26andsimple_monitor.py:18-24
Vulnerability Type: Hardcoded authentication secret
Risk Level: HighVulnerable Code
python EMAIL_CONFIG = { "smtp_server": "smtp.qq.com", "smtp_port": 587, "from_email": "57189896@qq.com", "to_email": "57189896@qq.com", "auth_code": "dskokcscwmkdbhjg" }The credential is actively used by the mail-sending implementation at
scripts/blackswan_monitor.py:72-84:python def send_email(subject, body): """发送邮件""" try: msg = MIMEMultipart() msg['From'] = EMAIL_CONFIG['from_email'] msg['To'] = EMAIL_CONFIG['to_email'] msg['Subject'] = subject msg.attach(MIMEText(body, 'plain', 'utf-8')) server = smtplib.SMTP(EMAIL_CONFIG['smtp_server'], EMAIL_CONFIG['smtp_port']) server.starttls() server.login(EMAIL_CONFIG['from_email'], EMAIL_CONFIG['auth_code']) server.send_message(msg) server.quit()Technical Analysis
A reusable QQ SMTP authorization code is embedded directly in three source files. Any person or process capable of reading the package can recover the email address and authorization secret without needing access to the original deployment environment.
Although SMTP transport is upgraded with STARTTLS, transport encryption does not protect a credential that has already been disclosed in source code. The presence of the same secret in multiple implementations also increases the likelihood that credential rotation will be incomplete.
Attack Path
- An attacker downloads, clones, or otherwise obtains read access to the project.
- The attacker searches the source for
auth_codeorserver.login. - The attacker extracts the hardcoded email address and SMTP authorization code.
- The attacker connects to
smtp.qq.comand attempts authentication ...[truncated 826 chars]
- Remediation
View remediation
Remediation Suggestions
- Revoke the exposed QQ SMTP authorization code immediately and issue a replacement only if email delivery remains necessary.
- Remove the credential from every source file and from repository history.
- Load SMTP credentials from a secret manager or protected environment variable, for example:
python EMAIL_CONFIG = { "smtp_server": os.getenv("SMTP_SERVER", "smtp.qq.com"), "smtp_port": int(os.getenv("SMTP_PORT", "587")), "from_email": os.environ["SMTP_FROM_EMAIL"], "to_email": os.environ["SMTP_TO_EMAIL"], "auth_code": os.environ["SMTP_AUTH_CODE"], }- Fail safely when required secrets are absent rather than falling back to embedded values.
- Restrict access to deployment secrets and avoid printing them in logs or exception output.
- Add automated secret scanning to source-control and CI workflows.
- Consolidate email configuration into one module so future credential rotation cannot leave stale copies.
