T09 · Insecure Skill Coding Practices
- Location
lib/auth-web.js:15- Finding
TLS Certificate Verification Disabled for Authentication Requests
- Content
View full analysis
Vulnerability Details
File Location:
lib/auth-web.js:15-27
Vulnerability Type: Improper certificate validation
Risk Level: Highjs this.httpClient = axios.create({ baseURL: 'https://115.com', timeout: 10000, headers: { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36', 'Accept': 'application/json, text/plain, */*', 'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8', 'Referer': 'https://115.com/' }, httpsAgent: new https.Agent({ rejectUnauthorized: false }) });Technical Analysis
The authentication client explicitly sets
rejectUnauthorizedtofalse. This causes Node.js to accept expired, self-signed, incorrectly named, or attacker-generated certificates instead of validating the server certificate against trusted certificate authorities.This client is used to generate login QR codes and poll login status. Consequently, the disabled validation affects an authentication-sensitive communication channel. HTTPS encryption alone does not provide server authenticity when certificate validation is disabled.
Attack Path
- An attacker obtains a network interception position, such as control of a malicious Wi-Fi access point, compromised proxy, DNS response, or upstream network device.
- The attacker redirects traffic intended for
https://115.comto an attacker-controlled HTTPS server. - The attacker presents an untrusted or self-signed certificate.
- The application accepts the certificate because
rejectUnauthorizedis disabled. - The attacker supplies forged QR-code or login-status responses, observes authentication state, or captures authentication artifacts transmitted through this client.
Impact Assessment
Successful exploitation compromises the confidentiality and integrity of the web authentication flow. An attacker may manipulate the QR code presente ...[truncated 231 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the custom HTTPS agent and use Node.js certificate validation defaults.
- Never set
rejectUnauthorized: falsein production or authentication code. - If a private trust chain is genuinely required, configure a narrowly scoped trusted CA bundle rather than disabling verification.
- Consider certificate or public-key pinning only if the service has an appropriate certificate-rotation strategy.
- Add an automated test confirming that connections with self-signed, expired, or hostname-mismatched certificates fail.
- Ensure fallback authentication implementations follow the same certificate-validation policy.
