T09 · Insecure Skill Coding Practices
- Location
nc_worker.py:8- Finding
Hard-Coded Nextcloud Credentials and Plaintext WebDAV Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
nc_worker.py, lines 8–10
Vulnerability Type: Hard-coded credentials and insecure transport configuration
Risk Level: Highpython NC_URL = "http://fedora:8082/remote.php/dav" # Via proxy/internal network if available, or replace with real URL USER = "receipts" PASS = "yu9cZvCVtctkhg3!"Technical Analysis
A reusable Nextcloud username and password are embedded directly in distributed source code. Any person or process able to read the project can recover these credentials without authentication. Secrets committed to source code may also remain available through package copies, caches, backups, and version-control history after removal.
The configured WebDAV endpoint uses plaintext HTTP rather than HTTPS. If the worker's planned WebDAV operations are implemented using these constants, authentication headers and private receipt data could traverse the network without transport encryption. An attacker with a suitable network position could observe or manipulate that traffic.
The relevant worker functions are currently stubs, so this artifact does not itself perform the network requests. Nevertheless, the exposed credentials can be used independently if the service is reachable, and the configuration creates an unsafe implementation path.
Attack Path
- An attacker obtains read access to the skill package or another copy of its source.
- The attacker opens
nc_worker.pyand extracts the Nextcloud URL, username, and password. - If the
fedora:8082service is reachable from the attacker's environment, the attacker authenticates to the WebDAV endpoint with the exposed credentials. - The attacker attempts operations permitted to the
receiptsaccount, potentially including listing, downloading, modifying, or deleting receipt files. - Separately, once the planned WebDAV code is implemented, an attacker positioned on the relevant network path could intercept or tamper with plaintext HTTP tra ...[truncated 622 chars]
- Remediation
View remediation
Remediation Suggestions
- Immediately revoke and rotate the exposed password. Treat it as compromised even if the repository was intended to be private.
- Remove credentials from source code and all retained repository history, package archives, build artifacts, logs, and backups where feasible.
- Retrieve credentials at runtime from a dedicated secret manager or protected environment variables. Do not provide insecure fallback values.
- Replace the endpoint with an
https://URL and enforce TLS certificate and hostname verification. The application should fail closed when secure transport cannot be established. - Use a dedicated service account with least-privilege access restricted to the exact receipt folder and required WebDAV operations.
- Prefer a short-lived application token over the account's primary password. Establish a regular rotation policy.
- Add secret scanning to pre-commit and CI pipelines to prevent credentials from entering future releases.
- Ensure implemented HTTP requests use explicit connection and read timeouts, reject redirects to untrusted or plaintext destinations, and avoid logging authorization headers or receipt contents.
- Audit Nextcloud access logs for use of the exposed account and investigate unexpected file access or modification.
