T09 · Insecure Skill Coding Practices
- Location
SKILL.md:54- Finding
Authentication Cookies Copied to Predictable Temporary Paths
- Content
View full analysis
/dev/null || true cp "$COOKIE_SOURCE" ~/.cache/rod/browser/cookies.json echo "Cookie 文件已放置到:" find /tmp -name "cookies.json" 2>/dev/null find ~ -name "cookies.json" 2>/dev/null | head -5 ``` ### Technical Analysis The documented repair procedure duplicates an authentication cookie file into several predictable locations, including `/tmp/cookies.json` and `/tmp/cookies/cookies.json`. It does not establish restrictive directory or file permissions, validate the ownership of existing destination paths, reject symbolic links, or ensure atomic file creation. Because `/tmp` is normally shared and writable by multiple local users, an attacker may prepare destination paths or symbolic links before the procedure runs. The `mkdir -p` and `cp` commands do not adequately protect against an attacker-controlled existing path. Copying the same credentials to multiple locations also increases their exposure and makes secure deletion and access control more difficult. ### Attack Path 1. A local attacker predicts that the repair procedure will write to `/tmp/cookies.json` or `/tmp/cookies/cookies.json`. 2. The attacker monitors the destination or prepares an attacker-controlled path or symbolic link where filesystem permissions permit it. 3. A user runs the documented cookie repair procedure. 4. The procedure copies active authentication cookies into the predictable destination without ownership or symlink validation. 5. The attacker reads the copied file or causes it to be written to an ...[truncated 839 chars]- Remediation
View remediation
` or another private service directory. - Create the directory with mode `0700` and cookie files with mode `0600`. - Set a restrictive `umask`, such as `umask 077`, before creating credential files. - Create the destination atomically and reject pre-existing files, symbolic links, and paths with unexpected ownership. - Validate the source file's owner, type, and permissions before copying it. - Copy credentials only to the single location actually required by the application. - Avoid printing or broadly searching credential locations. - Remove obsolete copies securely and rotate the affected session credentials if exposure may already have occurred. ]]>
