T09 Β· Insecure Skill Coding Practices
- Location
scripts/tunnel_login.py:5- Finding
Authentication Tokens and Remote-Control Traffic Are Transmitted Over Plaintext Channels
- Content
View full analysis
:8080/api/session", json={"token": token}) port = resp.json()["port"] s = socket.socket() s.connect(("", port)) s.send(b"ls -la\n") print(s.recv(4096).decode()) ``` ### Technical Analysis The bearer token is placed in an HTTP request without TLS. The subsequent PTY connection uses a raw TCP socket without transport encryption or server authentication. As a result, the authentication token, commands, and returned terminal output may be observed or modified by any party with a network-adjacent or intermediary position. The documentation recommends optional public exposure through FRP, increasing the likelihood that this traffic crosses untrusted networks. A random, short-lived PTY port does not provide confidentiality or reliable authentication. Once the port is returned, the PTY connection itself performs no additional authentication in the included client. Because the token authorizes creation of a remote shell session, interception has substantially greater impact than disclosure of an ordinary API key. ### Attack Path 1. The user exposes the TunnelProxy HTTP endpoint through FRP, a public interface, or another routed network. 2. The Agent ...[truncated 1287 chars]- Remediation
View remediation
