T09 · Insecure Skill Coding Practices
- Location
references/cli-reference.md:181- Finding
API Credentials Exposed Through URL Query Parameters
- Content
View full analysis
&password=` to generate a key, then pass `&key=` on subsequent requests. - REST API (PAN-OS 9.1+) provides a more modern interface at `/restapi/v10.x/` with JSON responses. Supports the same read-only operations. ``` ### Technical Analysis The documentation instructs operators to place an account password in an HTTP URL query string and to transmit the resulting API key through another query parameter. Although HTTPS protects these values while in transit, query strings are commonly retained outside the encrypted transport channel by: - Shell history and command history - HTTP client diagnostics and verbose output - Management-plane, reverse-proxy, and access logs - Monitoring, tracing, and observability systems - Browser history, copied URLs, and support bundles - Audit artifacts or terminal transcripts Anyone with access to such records may recover a reusable password or API key. The recommendation to use a dedicated read-only account limits potential modification privileges, but it does not eliminate unauthorized access to sensitive firewall information. ### Attack Path 1. An administrator follows the documented example and constructs a key-generation URL containing the username and password. 2. The request URL is retained in shell history, HTTP diagnostics, proxy logs, terminal recordings, or another operational record. 3. The generated API key is subsequently included in query strings and may be retained through the same mechanisms. 4. An attacker obtains access to one of these records through a compromised workstation, log platform, support archive, or overly broad log permissions. 5. The attacker extracts the password or API key. 6. The attacker authe ...[truncated 936 chars]- Remediation
View remediation
