T09 · Insecure Skill Coding Practices
- Location
src/baidu_search/main.py:42- Finding
Unauthenticated Search Endpoint Exposes the Operator's Baidu API Quota
- Content
View full analysis
SearchResponse: """ 搜索网页 - **query**: 搜索关键词 - **top_k**: 返回结果数量 (1-20, 默认 10) - **recency_filter**: 时间过滤 (day, week, month, year) - **site_filter**: 限定搜索的网站列表 """ return search(request) if __name__ == "__main__": import uvicorn uvicorn.run("baidu_search.main:app", host="0.0.0.0", port=8001) ``` ### Technical Analysis When this module is executed directly, Uvicorn binds the application to `0.0.0.0`, making it reachable through every available network interface. The `/search` endpoint has no authentication, authorization, request throttling, or usage quota. Every accepted request is forwarded to Baidu using the server operator's `BAIDU_API_KEY`. Consequently, any client that can reach TCP port 8001 can consume the operator's upstream API quota without possessing that credential. This runtime behavior is also less restrictive than the setup command in `SKILL.md`, which binds the documented service to `127.0.0.1`. ### Attack Path 1. The operator starts the application by running `src/baidu_search/main.py` directly. 2. The service listens on `0.0.0.0:8001`. 3. An attacker discovers or otherwise reaches port 8001. 4. The attacker repeatedly sends valid JSON requests to `POST /search`. 5. The application authenticates each upstream request with the operator's Baidu API key. 6. The attacker consumes the operator's API quota, potentially generating charges or exhausting service capacity. ### Impact Assessment An unauthenticated remote user can invoke the upstream search service under the operator's identity. The attacker does not obtain the literal API key or local operating-system privileges, but can abuse the author ...[truncated 184 chars]- Remediation
View remediation
