T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Unencrypted Transmission of Sensitive Database Queries and Results
- Content
View full analysis
LIMIT 100 OFFSET 0"}' \ "http://192.168.5.85:8000/query" ``` The mapping file also provides commands that query sensitive incident categories over the same cleartext endpoint: ```bash # 查询家庭纠纷数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_w8ZsC0='"'"'家庭纠纷'"'"'"}' "http://192.168.5.85:8000/query" # 查询婚姻纠纷数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_w8ZsC0='"'"'婚姻纠纷'"'"'"}' "http://192.168.5.85:8000/query" # 查询家暴数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_Wkv9nZ='"'"'家暴'"'"'"}' "http://192.168.5.85:8000/query" # 查询出轨数据 curl -X POST -H "Content-Type: application/json" -d '{"sql": "SELECT * FROM chujingxinxibiao_Sheet1_1732674000130 WHERE f_Wkv9nZ='"'"'出轨'"'"'"}' "http://192.168.5.85:8000/query" ``` ### Technical Analysis The documented API endpoint uses plain HTTP rather than HTTPS. Consequently, neither the SQL request nor the database response receives transport-layer confidentiality or integrity protection. The example queries target police incident information and sensitive dispute categories. Any party capable of observing or modifying traffic between the agent and `192.168.5.85:8000` could inspect the submitted SQL and returned records. An active network attacker could also modify a response, inject fabricated records, or redirect analysis toward misleading data. No API authentication or response-integrity mechanism is shown in the supplied commands. Although the address is on a private network, pri ...[truncated 1258 chars]- Remediation
View remediation
