T09 · Insecure Skill Coding Practices
- Location
scripts/mock_server.py:8- Finding
Intentionally Vulnerable Mock Server Listens on All Network Interfaces
- Content
View full analysis
Vulnerability Details
File Location:
scripts/mock_server.py:8-13, 31-43, 54-58
Vulnerability Type: Externally reachable test service with predictable credentials and a fixed token
Risk Level: MediumComplete Code Snippet
python # Allow port to be configurable via command line PORT = 18789 if len(sys.argv) > 1: try: PORT = int(sys.argv[1]) except ValueError: pass def do_POST(self): if self.path == '/login': content_length = int(self.headers['Content-Length']) post_data = self.rfile.read(content_length) try: data = json.loads(post_data.decode()) # Default credentials simulation if data.get('username') == 'admin' and data.get('password') == 'openclaw': self.send_response(200) self.send_header('Content-type', 'application/json') self.end_headers() self.wfile.write(b'{"token": "secret_token_123"}') else: self.send_response(401) self.end_headers() self.wfile.write(b'{"error": "Invalid credentials"}') except: self.send_response(400) self.end_headers() if __name__ == "__main__": # Allow address reuse socketserver.TCPServer.allow_reuse_address = True with socketserver.TCPServer(("", PORT), OpenClawHandler) as httpd: print(f"Mock OpenClaw server running on port {PORT}") try: httpd.serve_forever()Technical Analysis
Passing an empty host string to
socketserver.TCPServerbinds the mock server to all available network interfaces rather than restricting it to the loopback interface. The server intentionally recognizes the predictableadmin/openclawcredential pair and returns the fixed tokensecret_token_123.This behavior is test infrastructure and is not invoked by ...[truncated 1728 chars]
- Remediation
View remediation
Remediation Suggestions
- Bind the mock server to the loopback interface:
python with socketserver.TCPServer(("127.0.0.1", PORT), OpenClawHandler) as httpd: - Require an explicit test-only confirmation flag before starting the server.
- Print a prominent warning if a non-loopback bind address is requested.
- Avoid fixed token-like values. Generate an ephemeral value at startup or use an unmistakable placeholder that cannot be confused with a real credential.
- Move the server into a dedicated
tests/directory and document that it must not be used in production. - Consider rejecting remote clients even when a caller accidentally changes the bind address.
- Validate that the selected port is within
1-65535and fail closed on invalid input rather than silently retaining the default.
- Bind the mock server to the loopback interface:
