T09 · Insecure Skill Coding Practices
- Location
scripts/deploy_dsh.py:54- Finding
Security-group peers can bypass the SSH tunnel and access the dsh Web UI
- Content
View full analysis
Vulnerability Details
File Location:
scripts/deploy_dsh.py:54-65;scripts/coc_deploy.py:218-244;scripts/coc_deploy.py:252-259
Vulnerability Type: Network access-control bypass caused by a self-referencing security-group rule and an externally listening reverse proxy
Risk Level: HighVulnerable Code
python # scripts/deploy_dsh.py:54-65 if existing_sg: sg_id = existing_sg.get("id") print(f"✅ Using existing security group: {sg_name} ({sg_id})") return sg_id sg_id = client.create_security_group(sg_name, vpc_id) if not sg_id: print("❌ Failed to create security group") return None client.add_security_group_rule( sg_id, remote_group_id=sg_id, description="Allow all IPv4 traffic within security group" ) client.add_security_group_rule( sg_id, ip_version="IPv6", remote_group_id=sg_id, description="Allow all IPv6 traffic within security group" )nginx # scripts/coc_deploy.py:218-244 cat > /etc/nginx/conf.d/dsh.conf << 'NGINXEOF' server { listen 80; server_name _; client_max_body_size 50M; location / { proxy_pass http://127.0.0.1:%%DSH_PORT%%; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_read_timeout 3600s; proxy_send_timeout 3600s; } } NGINXEOFbash # scripts/coc_deploy.py:252-259 if command -v ufw > /dev/null 2>&1; then ufw allow 22/tcp > /dev/null 2>&1 || true ufw allow 80/tcp > /dev/null 2>&1 || true ufw allow 443/tcp > /dev/null 2>&1 || true echo "[$(date)] UFW: allowed 22/80/443" else echo "[$(date)] No UFW found; ensure cloud security group opens ports 22/80/443" fiTechnical Analysis
The deployment claims t ...[truncated 2823 chars]
- Remediation
View remediation
Remediation Suggestions
- Bind the reverse proxy to loopback explicitly:
nginx listen 127.0.0.1:80; listen [::1]:80;- Remove the UFW allowances for ports 80 and 443 when access is intended exclusively through an SSH tunnel:
bash ufw delete allow 80/tcp ufw delete allow 443/tcp-
Do not create unrestricted self-referencing ingress rules. If peer communication is genuinely required, restrict it to the exact protocol and port needed. For this deployment, no peer ingress rule is necessary for the SSH-tunnel design.
-
Create a unique security group per deployment, or validate every rule before reusing
sg-dsh. Do not rely only on the group name. -
Fail deployment if the selected security group contains ingress rules broader than the documented policy.
-
Add an automated post-deployment check that attempts to connect to ports 80 and 3080 through the instance's private interface and fails the deployment if either is reachable.
-
If private-network Web UI access is intentionally supported, document it explicitly and add application-layer authentication rather than representing the service as SSH-tunnel-only.
