T09 · Insecure Skill Coding Practices
- Location
SKILL.md:32- Finding
Reusable Authentication Token Transmitted Over Plaintext HTTP
- Content
View full analysis
"}') TOKEN=$(echo "$RESPONSE" | grep -oP 'Set-Cookie:.*token=\K[^;]+') # ALL subsequent requests must carry the token cookie curl -s -X GET http://{ip}/cgi-bin/entry.cgi/system/device-info \ -H "Cookie: token=$TOKEN" ``` The unsafe requirement is also reinforced by `API_REFERENCE.md:47`, which directs clients to reuse the JWT cookie without requiring TLS: ```text On success, the response header includes `Set-Cookie` with the JWT token. All subsequent requests must include `Cookie: token={jwt_token}`. ``` ### Technical Analysis The Skill logs in and sends subsequent authenticated requests using unencrypted `http://` connections. Although the login password is RSA-encrypted, the returned JWT is a reusable bearer credential. Possession of the token is sufficient to authenticate, so application-layer encryption of the password does not protect the session after login. An attacker capable of observing local network traffic can read the `Set-Cookie` response or a later `Cookie: token=...` request and replay the token. An active network attacker could also modify plaintext responses or requests. The browser guidance at `SKILL.md:43-45` additionally recommends checking `document.cookie` for the token. This assumes that the authentication cookie is script-readable rather than `HttpOnly`, increasing exposure if the device web interface contains a cross-site scripting vulnerability. ### Attack Path 1. A user or agent follows the Skill and logs in to a reCamera device over plaintext HTTP. 2. An attacker obtains a network-adjacent position, such as access ...[truncated 1609 chars]- Remediation
View remediation
