T09 · Insecure Skill Coding Practices
- Location
scripts/ip_lookup.py:25- Finding
API Key and Queried IP Addresses Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ip_lookup.py, lines 25 and 113–117
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: HighVulnerable code:
python API_URL = "http://apis.juhe.cn/ip/ipNewV3"python params = urllib.parse.urlencode({"key": api_key, "ip": ip}) url = f"{API_URL}?{params}" try: with urllib.request.urlopen(url, timeout=10) as resp: data = json.loads(resp.read().decode("utf-8"))Technical Analysis
The script includes the Juhe API key and user-supplied IP address in a URL query string sent over unencrypted HTTP. Because TLS is not used, network observers can read both values. An active man-in-the-middle can also modify API responses or redirect traffic, potentially causing the script to present forged geolocation data.
Transmitting queried public IP addresses to the declared Juhe service is necessary for the Skill's stated functionality. However, plaintext transport is not necessary and exceeds an acceptable least-exposure design. The Skill documentation itself shows an HTTPS endpoint, confirming that protected transport is expected.
Query-string credentials may additionally be captured by intermediary proxy logs or other URL-logging infrastructure.
Attack Path
- A user invokes the script with a valid Juhe API key and one or more public IP addresses.
- The script constructs an HTTP URL containing both the API key and queried IP address.
- An attacker observes or controls a network segment between the client and API service, such as an untrusted Wi-Fi network, compromised gateway, or transparent proxy.
- The attacker captures the plaintext request and extracts the API key and lookup target.
- The attacker can reuse the key to consume the victim's API quota.
- If actively intercepting traffic, the attacker can alter the response and cause the script to display false location or ISP information.
...[truncated 397 chars]
- Remediation
View remediation
Remediation Suggestions
- Change the endpoint to
https://apis.juhe.cn/ip/ipNewV3. - Do not implement fallback or downgrade to plaintext HTTP.
- Retain normal TLS certificate and hostname verification.
- If supported by the provider, transmit the credential through an authorization header or request body rather than a query string.
- Avoid logging complete request URLs containing credentials.
- Rotate any API key that may previously have been used over the plaintext endpoint.
- Add a test asserting that the configured API URL uses the
httpsscheme.
- Change the endpoint to
