T09 · Insecure Skill Coding Practices
- Location
xianyu-monitor-final.sh:112- Finding
Buyer-Controlled Chat Text Can Trigger Unauthorized Key Delivery
- Content
View full analysis
&1) # 检查是否为付款消息 if echo "$snapshot" | grep -q "我已付款\|等待你发货\|去发货"; then log "💰 检测到付款消息!" return 0 fi return 1 } ``` ### Technical Analysis The regular expression uses alternatives, so the condition succeeds if the page snapshot contains any one of the following phrases: - “I have paid” - “Waiting for you to ship” - “Ship now” It does not establish that the matching text belongs to an authentic Xianyu system payment card. It also does not require the payment message and fulfillment button to appear together or verify the order through an authoritative order record. Because ordinary buyer messages are included in the browser snapshot, a buyer can provide one of the accepted phrases as chat content. The script may then classify that buyer-controlled message as proof of payment. This contradicts the stricter documented design, which states that payment text and the fulfillment button should both be present and that ordinary user-written text should be excluded. ### Attack Path 1. An attacker opens a chat with the seller. 2. The attacker sends a message containing one accepted phrase, such as the equivalent of “I have paid.” 3. The monitor detects the recent conversation and enters it. 4. `analyze_chat` captures a snapshot containing the attacker’s message. 5. The alternation-based `grep` condition returns success. 6. The main loop calls `send_key`. 7. A key is removed from the seller’s pool and typed into the chat despite the absence of a verified payment. ### Impact Assessment A remote Xianyu user may obtain digital goods without making a valid payment. The attacker does not gain operating-system privileges, but can cause unauthorized business actions ...[truncated 315 chars]- Remediation
View remediation
