T09 · Insecure Skill Coding Practices
- Location
SKILL.md:193- Finding
Insecure Password Comparison, Predictable Session Tokens, and Sensitive User Object Exposure
- Content
View full analysis
_ ``` Neither component has sufficient unpredictability for an authentication credential. User IDs are commonly enumerable, and login timestamps can often be estimated within a narrow time window. The token therefore lacks the cryptographic entropy expected of a bearer credential. The response also returns the complete database record through `user`. Because the record was obtained with `select *`, it is likely to include the password field and other internal account attributes. ### Attack Path 1. An attacker determines or estimates the target's numeric user ID. 2. The attacker identifies an approximate time at which the target logged in, such as through observable user activity or a login event triggered by social engineering. 3. The attacker generates candidate tokens using the documented `token__` pattern. 4. The attacker submits candidates in the `Authorization` header to protected endpoints. 5. If a candidate matches a token s ...[truncated 828 chars]- Remediation
View remediation
