T09 · Insecure Skill Coding Practices
- Location
scripts/xiaopai-ctl.sh:69- Finding
Unrestricted User-Controlled Network Destination
- Content
View full analysis
/dev/null || echo '{"error":"connection failed"}' ``` ### Technical Analysis The first command-line argument is treated as the player IP and used directly as the destination for `curl` and `nc`. The script does not establish that the value is a valid IP address, belongs to an approved LAN range, or corresponds to a XiaoPai device discovered through mDNS. Although the destination ports are fixed to HTTP port 9050 and TCP port 9051, an attacker who can influence the arguments passed by the Agent can cause connections to arbitrary reachable hosts on those ports. This creates a constrained arbitrary-network-request primitive and violates the documented assumption that commands are directed only to a XiaoPai player on the same LAN. The use of shell quoting prevents ordinary shell command injection through this parameter, but it does not prevent network destination manipulation. ### Attack Path 1. An attacker induces the Agent to invoke the Skill with an attacker-selected hostname or IP address. 2. The value is assigned directly to `IP`. 3. For control operations, the script constructs an HTTP URL from that value and invokes `curl`. 4. For status operations, the script passes the value directly to `nc`. 5. The host running the Skill connects to the selected destination on port 9050 or 9051. 6. The attacker can use the resulting behavior to probe reachable services or send XiaoPai-compatible requ ...[truncated 582 chars]- Remediation
View remediation
