T09 · Insecure Skill Coding Practices
- Location
scripts/query_storage.py:129- Finding
Blockchain account queries use an unencrypted HTTP connection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/query_storage.py, lines 129-141 and 279-281
Vulnerability Type: Plaintext transmission of account query data
Risk Level: Mediumpython def rpc_call(method: str, params: list, api_url: str = "http://api.hippius.io") -> Optional[Dict[str, Any]]: payload = { "jsonrpc": "2.0", "method": method, "params": params, "id": 1 } headers = {"Content-Type": "application/json"} try: request = Request( api_url, data=json.dumps(payload).encode('utf-8'), headers=headers )python rpc_group.add_argument( "--api-url", default="http://api.hippius.io", help="Hippius RPC API URL (default: http://api.hippius.io)" )Technical Analysis
The default RPC endpoint uses plaintext HTTP. Calls to
get_user_files,calculate_total_file_size, andget_free_credits_rpctransmit the supplied account address and requested operation without transport encryption or server authentication.An on-path attacker can observe account identifiers and query activity, impersonate the RPC service, or modify returned file metadata, storage totals, and credit balances. Although the command-line parser exposes an
--api-urloption,args.api_urlis never passed torpc_call; therefore, this option does not allow users to replace the insecure default in the current implementation.Sending an account address to an RPC service is relevant to the declared functionality, but sending it through plaintext HTTP exceeds the minimum risk necessary because authenticated HTTPS should be used.
Attack Path
- A user invokes the script with
--account, optionally selecting file, storage, or credit queries. - The script creates a JSON-RPC request containing the account address and query method.
- The request is sent to
http://api.hippius.ioover an unen ...[truncated 727 chars]
- A user invokes the script with
- Remediation
View remediation
Remediation Suggestions
- Change the default endpoint to a verified
https://URL. - Pass
args.api_urlthrough the query functions and into everyrpc_call. - Parse and validate the configured URL before making a request.
- Reject plaintext HTTP for non-loopback destinations.
- If development over HTTP is necessary, restrict it to explicit loopback addresses such as
127.0.0.1orlocalhostand require an opt-in flag. - Continue using standard certificate and hostname verification; do not add an option that silently disables TLS verification.
- Add tests confirming that remote HTTP endpoints are rejected and the selected HTTPS endpoint is actually used.
- Change the default endpoint to a verified
