T09 · Insecure Skill Coding Practices
- Location
references/troubleshooting-dns.md:67- Finding
TLS Certificate Verification Disabled for Authenticated Cloud API Requests
- Content
View full analysis
Vulnerability Details
File Location:
references/troubleshooting-dns.md, lines 67–74
Vulnerability Type: Improper Certificate Validation
Risk Level: MediumVulnerable snippet:
bash ## Alternative (when you prefer not to modify /etc/hosts) - Add `--cli-endpoint` to point hcloud at the public IP (note: may fail due to certificate SNI mismatch; prefer the /etc/hosts approach): ```bash hcloud CES ListMetrics --cli-region=cn-north-4 --namespace=SYS.ECS \ --cli-endpoint=https://120.46.246.26 --cli-skip-secure-verify=true ...text ### Technical Analysis The documented fallback directs users to connect to a cloud API endpoint by IP address while passing `--cli-skip-secure-verify=true`. This disables verification of the endpoint's TLS certificate and prevents the client from confirming that it is communicating with the legitimate Huawei Cloud service. Although the primary `/etc/hosts` approach retains the service hostname, the alternative remains an actionable installation and troubleshooting instruction. When followed, any network-positioned attacker capable of intercepting or redirecting traffic can present an arbitrary certificate without the CLI rejecting the connection. The request is made by a configured Huawei Cloud CLI and may therefore contain signed authentication metadata. The demonstrated `ListMetrics` operation is read-only, but an interceptor can observe the authenticated request and return forged API data. If the same documented pattern is applied to the Skill's metric-collection operations, forged monitoring responses can influence the calculated capacity results and scale-out recommendations. ### Attack Path 1. The user configures `hcloud` with Huawei Cloud credentials as instructed by the Skill. 2. A DNS or SNI connectivity problem causes the user to follow the alternative troubleshooting procedure. 3. The user invokes `hcloud` with a direct-IP endpoint and `--cli-skip-secure-verify=true`. 4. An attacker with cont ...[truncated 1257 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
--cli-skip-secure-verify=truefrom all documented commands. - Require the original Huawei Cloud service hostname to remain the TLS verification and SNI hostname.
- Prefer a controlled DNS correction or a carefully verified
/etc/hostsmapping so certificate validation remains enabled. - For connectivity testing, use
curl --resolvewithout-k, preserving both the hostname and certificate verification. - Verify candidate public IP addresses through an approved DNS resolver or authoritative cloud documentation before changing host resolution.
- If direct-IP operation cannot preserve hostname-based certificate verification, fail securely and instruct the user to correct DNS rather than bypass TLS validation.
- Warn users not to generalize certificate-verification bypasses to authenticated metric-collection commands.
- Remove
