T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/get_myipchecker_ip_info.sh:4- Finding
Unrestricted Base URL and Redirect Following Enable Server-Side Request Forgery
- Content
View full analysis
&2 exit 2 fi BASE_URL=$2 shift 2 ;; ``` ```sh BASE_URL=${BASE_URL%/} URL="$BASE_URL/api/ip" ``` ```sh if [ -n "$IP" ]; then HTTP_STATUS=$(curl -sS -L -G \ -H "Accept: application/json" \ -H "User-Agent: $USER_AGENT" \ --connect-timeout "$TIMEOUT_SECONDS" \ --max-time "$TIMEOUT_SECONDS" \ --data-urlencode "ip=$IP" \ -o "$BODY_FILE" \ -w "%{http_code}" \ "$URL" 2>"$STATUS_FILE") else HTTP_STATUS=$(curl -sS -L \ -H "Accept: application/json" \ -H "User-Agent: $USER_AGENT" \ --connect-timeout "$TIMEOUT_SECONDS" \ --max-time "$TIMEOUT_SECONDS" \ -o "$BODY_FILE" \ -w "%{http_code}" \ "$URL" 2>"$STATUS_FILE") fi CURL_EXIT=$? if [ "$CURL_EXIT" -ne 0 ]; then REASON=$(cat "$STATUS_FILE") printf '{\n "transport_error": "request_error",\n "reason": "%s",\n "url": "%s"\n}\n' "$(json_escape "$REASON")" "$(json_escape "$URL")" exit 1 fi BODY=$(cat "$BODY_FILE") case "$HTTP_STATUS" in 2??) if [ -z "$BODY" ]; then printf '{\n "transport_error": "invalid_json",\n "url": "%s",\n "body": ""\n}\n' "$(json_escape "$URL")" exit 1 fi printf '%s\n' "$BODY" ;; *) printf '{\n "transport_error": "http_error",\n "status": %s,\n "reason": "HTTP %s",\n "url": "%s",\n "body": "%s"\n}\n' \ "$HTTP_STATUS" \ "$HTTP_STATUS" \ "$(json_escape "$URL")" \ "$(json_escape "$BODY")" exit 1 ;; esac ``` The skill do ...[truncated 3058 chars]- Remediation
View remediation
