T09 · Insecure Skill Coding Practices
- Location
scripts/check.sh:65- Finding
Unrestricted URL Requests Enable Server-Side Request Forgery and Internal Network Probing
- Content
View full analysis
/dev/null) ``` #### `scripts/quick.sh:61-63` ```python result = subprocess.run( ["curl", "-s", "-o", "/dev/null", "-w", "%{http_code}", "--max-time", str(timeout), "-L", "-I", url], capture_output=True, text=True, timeout=timeout + 2 ) ``` #### `scripts/affiliate.sh:70-72` ```python result = subprocess.run( ["curl", "-s", "-o", "/dev/null", "-w", "%{http_code}", "--max-time", str(timeout), "-L", "-I", url], capture_output=True, text=True, timeout=timeout + 2 ) ``` ### Technical Analysis The scripts extract URLs from HTML files supplied through a directory argument or the `SITE_DIR` environment variable and pass those URLs directly to `curl`. They do not validate the resolved destination before making the request. The implementations do not reject: - IPv4 or IPv6 loopback addresses - RFC1918 private-network addresses - Link-local addresses - Cloud instance metadata endpoints - Multicast, reserved, or otherwise non-public addresses - Hostnames that resolve to internal addresses - Public URLs that redirect to internal addresses The `-L` option instructs `curl` to follow redirects automatically. Consequently, validating only the original URL would not be sufficient: an apparently public URL can redirect the request to an internal service. Every redirect destination must be validated before it is contacted. The full checker is especially permissive because `scripts/check.sh` does not explicitly restrict extracted links to HTTP and HTTPS before passing them to `curl`. The two Python implementat ...[truncated 2549 chars]- Remediation
View remediation
