T09 · Insecure Skill Coding Practices
- Location
scripts/send_email.py:156- Finding
SMTP TLS Certificate Validation Is Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/send_email.py, lines 156–161
Vulnerability Type: Improper TLS certificate validation
Risk Level: HighVulnerable Code
python context = ssl.create_default_context() context.check_hostname = False context.verify_mode = ssl.CERT_NONE with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT, context=context) as server: server.login(from_email, auth_code) server.sendmail(from_email, all_recipients, msg.as_string())Technical Analysis
The code creates a TLS context but then explicitly disables hostname verification and certificate-chain validation. Consequently, the client encrypts its connection without authenticating that the remote endpoint is the legitimate
smtp.163.comserver.An attacker who can intercept or redirect network traffic can present an arbitrary certificate, and the client will accept it. The application then transmits the sender address, SMTP authorization code, recipient information, message content, and attachments through the attacker-controlled endpoint.
Attack Path
- An attacker obtains a network interception position or manipulates DNS/routing for
smtp.163.com. - The attacker redirects the SMTP connection to a server under their control.
- The malicious server presents an untrusted certificate or a certificate issued for a different hostname.
- The client accepts that certificate because hostname checking and certificate validation are disabled.
- The client submits the mailbox address and SMTP authorization code to the malicious endpoint.
- The attacker captures the credentials and email data, and may proxy or alter the SMTP exchange to reduce the chance of detection.
- The stolen authorization code may subsequently be used to access SMTP functionality and send email as the victim, subject to the mailbox provider's authorization scope and controls.
Impact Assessment
Successful exploitation c ...[truncated 523 chars]
- An attacker obtains a network interception position or manipulates DNS/routing for
- Remediation
View remediation
Remediation Suggestions
Preserve Python's secure TLS defaults and remove both assignments that disable validation:
python context = ssl.create_default_context() with smtplib.SMTP_SSL(SMTP_SERVER, SMTP_PORT, context=context) as server: server.login(from_email, auth_code) server.sendmail(from_email, all_recipients, msg.as_string())Additionally:
- Allow certificate or hostname validation failures to terminate transmission.
- Do not introduce an insecure fallback that retries with validation disabled.
- Use the operating system's maintained CA trust store, or explicitly configure a trusted CA bundle when required by the deployment environment.
- Add an integration test verifying that expired, self-signed, untrusted, and hostname-mismatched certificates are rejected.
- Rotate the SMTP authorization code if the application has previously operated over an untrusted network while certificate validation was disabled.
