T09 · Insecure Skill Coding Practices
- Location
scripts/analyser.py:123- Finding
Unencrypted Financial Data API Request
- Content
View full analysis
Vulnerability Details
File Location:
scripts/analyser.py:123-139
Vulnerability Type: Plaintext HTTP communication
Risk Level: MediumVulnerable Code
python url = f"http://datacenter-web.eastmoney.com/api/data/v1/get" params = { "sortColumns": "NET_BUY_AMT", "sortTypes": "-1", "pageSize": "50", "pageNumber": "1", "reportName": "RPT_DMSK_TS", "columns": "ALL", "filter": f"(TRADE_DATE='{date}')" } try: resp = self.session.get(url, params=params, timeout=10) data = resp.json() return data.get("result", {}).get("data", []) except: return []Technical Analysis
The
fetch_dragon_tiger()method retrieves financial ranking data through plaintext HTTP. HTTP does not provide transport confidentiality, server authentication, or response integrity. An attacker in a position to intercept network traffic could impersonate the data provider or modify the response in transit.The method immediately decodes and returns the response as JSON without checking the HTTP status, validating the response schema, or authenticating the source. Consequently, a forged response containing manipulated financial records could be accepted as legitimate application data.
Attack Path
- A user runs the stock analysis functionality on an attacker-controlled or otherwise compromised network.
- The application requests the Eastmoney endpoint over plaintext HTTP.
- A network-positioned attacker intercepts the request through techniques such as a malicious access point, compromised gateway, or DNS manipulation.
- The attacker returns a syntactically valid but manipulated JSON response.
resp.json()accepts the forged response, and the method returns attacker-controlled financial records.- Any downstream analysis or user decision based on those records may rely on false market information.
Impact Assessment
The issue allows a network-positioned attacker to compromise the integrity and confidentiality ...[truncated 474 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the plaintext endpoint with the provider's verified HTTPS endpoint:
python url = "https://datacenter-web.eastmoney.com/api/data/v1/get"- Keep TLS certificate verification enabled. Do not introduce
verify=False; where appropriate, explicitly use a trusted CA bundle. - Reject unsuccessful HTTP responses before parsing:
python resp = self.session.get(url, params=params, timeout=10) resp.raise_for_status()- Validate the response content type and enforce an expected JSON schema, including the types and permitted ranges of financial fields.
- Treat missing or malformed fields as an error rather than silently accepting partial data.
- Log failures without exposing sensitive information, and clearly mark unavailable data instead of using unverifiable results.
- Consider cross-checking high-impact market information against an independent authenticated data source before presenting actionable analysis.
