T09 · Insecure Skill Coding Practices
- Location
scripts/ctrip_flight.py:20- Finding
TLS Certificate and Hostname Verification Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ctrip_flight.py, lines 20–22; affected request sites at lines 173 and 206
Vulnerability Type: Improper Certificate Validation
Risk Level: MediumComplete code snippet:
python SSL_CTX = ssl.create_default_context() SSL_CTX.check_hostname = False SSL_CTX.verify_mode = ssl.CERT_NONEThe insecure context is used for both HTML and API requests:
python with urllib.request.urlopen( urllib.request.Request(url, headers={ "User-Agent": UA, "Accept": "text/html" }), timeout=15, context=SSL_CTX ) as resp:python with urllib.request.urlopen( urllib.request.Request( f"{url}?v={random.random()}", data=body, headers=headers, method="POST" ), timeout=15, context=SSL_CTX ) as resp:Technical Analysis
The script creates a standard TLS context but then explicitly disables hostname verification and certificate-chain validation. Consequently, HTTPS provides encryption without authenticating the remote endpoint.
This context is used when retrieving the
FVPcookie from Ctrip HTML and when submitting flight-search and low-price API requests. A network-positioned attacker capable of intercepting the connection can present an arbitrary certificate without causing validation failure. The script will parse the attacker's HTML or JSON as though it came from the configured Ctrip endpoints.Attack Path
- A user invokes the Skill to search for flights.
- The script connects to a fixed Ctrip HTTPS endpoint using
SSL_CTX. - An attacker controlling a relevant network path, proxy, DNS path, or compromised access point intercepts the connection.
- The attacker presents a forged certificate and returns crafted HTML or JSON.
- Because certificate and hostname verification are disabled, the response is accepted.
- Attacker-contro ...[truncated 847 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both verification-disabling assignments and retain the secure defaults:
python SSL_CTX = ssl.create_default_context() - Ensure
check_hostnameremains enabled andverify_moderemainsssl.CERT_REQUIRED. - Use the operating system's trusted CA store, or configure a narrowly scoped trusted CA bundle when required.
- Fail closed on certificate, hostname, and TLS negotiation errors; do not retry using an unverified context.
- If interception by an organizational proxy is required, install its CA through an explicit administrative trust process rather than disabling verification globally.
- Add tests confirming that expired, self-signed, wrong-host, and untrusted certificates are rejected.
- Remove both verification-disabling assignments and retain the secure defaults:
