T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_comments.py:267- Finding
Authenticated Douyin Requests Disable TLS Certificate Verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fetch_comments.py:197-203, 259-267
Vulnerability Type: Improper TLS certificate validation during authenticated requests
Risk Level: MediumVulnerable Code
python def _www_probe(cookies: dict, timeout: float = 8.0) -> str: """Probe the Douyin homepage using the same cookie.""" try: h = dict(_HEADERS) h["Cookie"] = "; ".join(f"{k}={v}" for k, v in cookies.items()) r = httpx.get("https://www.douyin.com/", headers=h, timeout=timeout, verify=False, follow_redirects=True) return f"status={r.status_code} len={len(r.text)}" except Exception as exc: return f"exc={type(exc).__name__}:{exc}"python headers = dict(_HEADERS) headers["user-agent"] = fp["ua"] headers["referer"] = cfg["referer_tpl"].format(aweme_id) headers["sec-fetch-site"] = cfg["sec_fetch_site"] headers["Cookie"] = "; ".join(f"{k}={v}" for k, v in cookies.items()) resp = httpx.get(final_url, headers=headers, timeout=timeout, verify=False)Technical Analysis
The HTTP comment collection path constructs a
Cookieheader containing the user-provided Douyin session cookies and sends it while explicitly settingverify=False. This disables certificate-chain and hostname validation, so the client cannot authenticate that it is communicating with the genuinecreator.douyin.comorwww.douyin.comserver.The main comment request at line 267 is reached whenever the user invokes authenticated HTTP comment collection. The
_www_proberequest at lines 197-203 is additionally reached when a comment response cannot be parsed. Both requests transmit the complete parsed cookie collection without valid TLS peer authentication.This is a regular exploitable implementation vulnerability rather than evidence of intentional credential theft. The configured destinations are consistent with the Skill’s decla ...[truncated 1621 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove
verify=Falsefrom the authenticated comment request:python resp = httpx.get(final_url, headers=headers, timeout=timeout) -
Restore certificate verification for the diagnostic probe:
python r = httpx.get( "https://www.douyin.com/", headers=h, timeout=timeout, follow_redirects=True, ) -
Remove the warning-suppression logic for insecure TLS requests so future certificate-validation regressions remain visible.
-
If a private enterprise certificate authority must be supported, accept an explicit trusted CA bundle rather than disabling verification:
python with httpx.Client(verify="/path/to/enterprise-ca.pem") as client: resp = client.get(final_url, headers=headers, timeout=timeout) -
Fail closed on certificate errors. Do not retry authenticated requests with validation disabled.
-
Add automated tests that intercept the request with an untrusted certificate and verify that both the main request and diagnostic probe reject the connection before transmitting authenticated application data.
-
