T09 · Insecure Skill Coding Practices
- Location
references/01-dev/ai-guide.md:8- Finding
Lindorm credentials transmitted over plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
references/01-dev/ai-guide.md:8-23
Vulnerability Type: Cleartext transmission of reusable credentials
Risk Level: HighVulnerable Code
markdown | Network type | Endpoint example | Applicable environment | |--------------|------------------|-------------------------| | VPC private network | `<instance_id>-proxy-ai-vpc.lindorm.aliyuncs.com:9002` | Search pipelines, ECS, and services inside the VPC | | Public network | `<instance_id>-proxy-ai-pub.lindorm.aliyuncs.com:9002` | Local computers or public-network clients | Before making public-network calls, confirm that the public endpoint of the AI engine is enabled and that the IP whitelist is configured. ### Connectivity check for port 9002 ```bash curl --connect-timeout 10 -m 60 \ -H 'Content-Type: application/json' \ -H 'x-ld-ak: <username>' \ -H 'x-ld-sk: <password>' \ -XPOST "http://<ai_endpoint>:9002/dashscope/compatible-mode/v1/embeddings" \text The same insecure pattern is repeated for model requests at lines 49-53, 87-91, 132-136, 184-188, and 230-234. ### Technical Analysis The guide instructs users to authenticate using a Lindorm username and password in the `x-ld-ak` and `x-ld-sk` HTTP headers. It then sends those headers to an `http://` URL without TLS. This workflow explicitly supports public endpoints for clients outside the VPC. When used over a public or otherwise untrusted network, HTTP provides neither confidentiality nor server authentication. An on-path attacker can inspect the request and recover the reusable Lindorm credentials. The attacker may also modify requests or responses in transit. The instruction at line 272 not to include passwords in reports only prevents output disclosure; it does not protect credentials during network transmission. Likewise, an IP whitelist restricts which clients may connect but does not encrypt traffic or prevent an on-path observer from reading the headers. ### Attack Path 1. ...[truncated 1284 chars]- Remediation
View remediation
Remediation Suggestions
-
Require HTTPS with certificate verification for every public AI endpoint example:
bash curl --fail --show-error \ --proto '=https' \ --tlsv1.2 \ -H 'Content-Type: application/json' \ -H "x-ld-ak: ${LINDORM_USERNAME}" \ -H "x-ld-sk: ${LINDORM_PASSWORD}" \ -X POST "https://<ai_endpoint>:<tls_port>/dashscope/compatible-mode/v1/embeddings" -
If the native service on port 9002 does not support TLS, explicitly prohibit direct public-network use. Require one of:
- A private VPC endpoint;
- A trusted VPN or private connection;
- An authenticated TLS reverse proxy or gateway that terminates TLS securely.
-
Remove examples that place literal passwords directly in shell command arguments. Load credentials from a protected secret store, restricted credential file, or environment supplied by a secrets manager.
-
Add a mandatory transport-security warning stating that IP allowlisting is not a substitute for encryption.
-
Update all repeated plaintext examples in this file, including lines 49-53, 87-91, 132-136, 184-188, and 230-234.
-
Rotate any credentials previously used over plaintext public connections and review relevant access logs for unauthorized activity.
-
