T09 · Insecure Skill Coding Practices
- Location
scripts/ip_intelligence.py:370- Finding
Plaintext HTTP Provider Request Permits Disclosure and Evidence Tampering
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ip_intelligence.py:370-382
Vulnerability Type: Plaintext transmission of lookup data and unauthenticated provider evidence
Risk Level: MediumVulnerable Code
python def lookup_ip_api(ip: str, timeout: float) -> Dict[str, Any]: fields = "status,message,country,countryCode,regionName,city,isp,org,as,asname,reverse,mobile,proxy,hosting,query" url = f"http://ip-api.com/json/{urllib.parse.quote(ip)}?fields={fields}" raw = request_json(url, timeout) if raw.get("status") != "success" or raw.get("query") != ip: raise LookupError(text_value(raw.get("message")) or "IP-API lookup failed") data = clean_data( country_code=raw.get("countryCode"), country=raw.get("country"), region=raw.get("regionName"), city=raw.get("city"), asn=normalize_asn(raw.get("as")), organization=first(raw, "asname", "org"), isp=raw.get("isp"), reverse_dns=raw.get("reverse"), is_mobile=boolean(raw.get("mobile")), is_proxy=boolean(raw.get("proxy")), is_hosting=boolean(raw.get("hosting")), ) return {"data": data, "raw": raw, "source_url": f"https://ip-api.com/#{ip}"}Technical Analysis
The adapter sends the investigated IP address over plaintext HTTP. Although
request_bytes()creates an SSL context, that context provides no protection for anhttp://URL. Consequently, both the request and response lack transport confidentiality and integrity.The target-echo check only verifies that the response contains the expected IP. An on-path attacker can preserve that value while modifying country, city, ASN, organization, ISP, reverse-DNS, proxy, mobile, or hosting fields. The modified fields are then accepted as provider evidence and can affect consensus facts and network-exposure conclusions.
The
source_urlrecorded in the result uses HTTPS, but the actual API request uses HTTP. This may also make the resulting ...[truncated 1210 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the plaintext endpoint with a provider endpoint that supports HTTPS.
- If no authenticated endpoint is available, disable this adapter by default and require explicit user opt-in.
- Clearly label any evidence collected over plaintext transport as unauthenticated and exclude it from security-sensitive consensus unless independently corroborated.
- Record the actual request endpoint and transport in report provenance instead of presenting only an HTTPS public-page URL.
- Add a centralized transport policy in
request_bytes()that rejects non-HTTPS URLs unless a narrowly scoped, explicitly documented exception is enabled. - Add tests confirming that provider adapters cannot silently issue HTTP requests.
