T09 · Insecure Skill Coding Practices
- Location
config.yaml:2- Finding
Hardcoded Credential for a Remote PostgreSQL Superuser Account
- Content
View full analysis
^bZsPIX}A&" options: "-c search_path=ioc" ``` The credential is consumed directly by the application in `scripts/generate_report.py:49-59`: ```python db_config = { "host": config["database"]["host"], "port": config["database"]["port"], "dbname": config["database"]["name"], "user": config["database"]["user"], "password": config["database"]["password"], } # If options are configured, add them. if "options" in config["database"]: db_config["options"] = config["database"]["options"] return psycopg2.connect(**db_config) ``` ### Technical Analysis The distributed configuration contains a usable-looking password together with a publicly addressable database hostname, nonstandard PostgreSQL port, database name, and username. Anyone who can read or download the Skill package can recover all information required to attempt authentication. The configured username is `postgres`, which conventionally identifies PostgreSQL's administrative superuser. The report generator only needs to execute aggregate `SELECT` queries, so using an administrative account substantially exceeds the minimum privileges required by the declared reporting functionality. The credential must be treated as compromised even if the database is currently protected by network filtering or the password is no longer valid. Copies may remain in package caches, repository history, audit logs, and downloaded Skill archives. ### Attack Path 1. An attacker downloads or otherwise obtains the Skill package. 2. The attacker opens `config.yaml` and extracts the host, port, database name, username, and password. 3. The attacker attempts a PostgreSQL connection to `hi ...[truncated 1249 chars]- Remediation
View remediation
