T09 · Insecure Skill Coding Practices
- Location
references/common-workflows.md:25- Finding
Public ECS Deployment Uses a Known Root Password with Internet-Wide SSH Access
- Content
View full analysis
Vulnerability Details
File Location:
references/common-workflows.md:25-43,references/common-workflows.md:73-80,references/common-workflows.md:93-105,references/common-workflows.md:350-355; related example inreferences/core-commands.md:53-64
Vulnerability Type: Hardcoded predictable administrative credential and excessive network exposure
Risk Level: HighVulnerable Code
bash # 5. Create instance hcloud ECS CreateServers \ --server.name=my-instance \ --server.imageRef=<image-id> \ --server.flavorRef=ac8.large.2 \ --server.vpcid=<vpc-id> \ --server.subnet_id=<subnet-id> \ --server.security_groups.1.id=<sg-id> \ --server.adminPass=MyP@ssw0rd123! \ --server.publicip.eip.bandwidth.sharetype=PER \ --server.publicip.eip.bandwidth.size=5 \ --server.publicip.eip.bandwidth.charge_mode=bandwidth \ --cli-region=cn-north-4 # 7. Verify SSH connection sshpass -p 'MyP@ssw0rd123!' ssh -o StrictHostKeyChecking=no root@<public-ip> "echo OK"The same workflow creates an Internet-wide SSH rule:
bash hcloud VPC CreateSecurityGroupRule/v3 \ --security_group_id=<sg-id> \ --security_group_rule.direction=ingress \ --security_group_rule.protocol=tcp \ --security_group_rule.multiport=22 \ --security_group_rule.remote_ip_prefix=0.0.0.0/0 \ --security_group_rule.description="Allow SSH" \ --cli-region=cn-north-4The document subsequently reinforces the literal as an example:
markdown 1. Use strong passwords (e.g., MyP@ssw0rd123!)A related core command also embeds a fixed administrative password:
bash hcloud ECS CreateServers \ --server.name=my-instance \ --server.imageRef=img-ubuntu-22-04 \ --server.flavorRef=ac8.large.2 \ --server.vpcid=vpc-12345678 \ --server.subnet_id=subnet-12345678 \ --server.adminPass=MySecurePass123! \ --server.security_groups.1.id=sg-12345678 \ --server.publicip.eip.bandwidth.sharetype=PER \ --server.publicip.eip ...[truncated 2231 chars]- Remediation
View remediation
Remediation Suggestions
- Replace every literal administrative password with a mandatory placeholder that cannot be mistaken for a usable credential.
- Prefer SSH public-key authentication and disable password-based root login.
- If a password is unavoidable, generate a unique high-entropy value for each instance through an approved secret-management mechanism. Do not place it in command history, source documents, logs, or Agent output.
- Restrict SSH ingress to a user-approved management CIDR, VPN, bastion host, or zero-trust access path. Do not use
0.0.0.0/0as the default. - Separate resource creation from network exposure and require the user to confirm the exact source CIDR before applying the security-group rule.
- Remove
MyP@ssw0rd123!andMySecurePass123!from all examples, including the statement that characterizes the former as a strong-password example. - Add post-deployment validation that checks for Internet-wide administrative ports and rejects or prominently warns about such configurations.
