T09 · Insecure Skill Coding Practices
- Location
scripts/monitor.py:24- Finding
Unrestricted Configurable URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
0: delay = RETRY_DELAY[min(attempt - 1, len(RETRY_DELAY) - 1)] print(f" 🔄 第{attempt + 1}次重试(等待{delay}秒)...") time.sleep(delay) response = requests.get(url, headers=headers, timeout=REQUEST_TIMEOUT) ``` The fetched URL is obtained from each site entry in the configuration: ```python for site in school['sites']: site_name = site['site_name'] url = site['url'] print(f" ▶ {site_name}: {url}") notices = get_exact_notices_for_site(site_name, url) ``` ### Technical Analysis The application treats URLs loaded from the editable `schools.json` file as trusted and passes them directly to `requests.get`. It does not validate: - The URL scheme. - The destination hostname. - The resolved IP address. - Loopback, private, link-local, multicast, or reserved address ranges. - Redirect destinations. - Whether the destination belongs to an approved university domain. Python Requests follows redirects by default. Consequently, validation limited only to an initial hostname would also be insufficient unless every redirect target is checked. A user, automation process, or agent capable of editing `schools.json` can configure URLs such as loopback services, private network hosts, or cloud instance metadata endpoints. The monitor then initiates the request using the network permissions of the proce ...[truncated 1812 chars]- Remediation
View remediation
