T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Hard-Coded API Signing Material and Weak Request-Signing Construction
- Content
View full analysis
str: return hashlib.md5((SALT + data).encode()).digest().hex() ``` The same hard-coded value is documented as the API signing salt: ```text Signing Salt: 68756c61 ``` ### Technical Analysis The Skill distributes the fixed value used to produce API request signatures and documents the complete signing algorithm. Anyone with access to the Skill can consequently generate the expected `sign` header for an arbitrary JSON request body. The construction `MD5(salt || message)` is not a modern message-authentication mechanism. The fixed salt is shared across installations, has no confidentiality after distribution, and provides no demonstrated key separation, timestamp validation, nonce, or replay protection. The documented session cookie remains an additional authentication requirement, so knowledge of the signing value alone does not establish an authenticated session. Nevertheless, disclosure of the signing construction removes one security layer and makes a stolen or otherwise exposed session substantially easier to use for forged inventory requests. ### Attack Path 1. Obtain a copy of the publicly distributed or otherwise accessible Skill. 2. Extract the hard-coded value `68756c61` and the documented MD5 signing procedure. 3. Obtain a valid `ASP.NET_SessionId` through a separate compromise, such as session leakage, endpoint exposure, or theft from an authorized user. 4. Construct an arbitrary inventory API request body, including a stock-out creation, update, or deletion request. 5. Serialize the body using the documented compact JSON format. 6. Calculate the expected signature using `MD5("68756c61" || serialized_body)`. 7. Submit the forged request with the stolen session cookie and calculated `sign` header. 8. If the serv ...[truncated 873 chars]- Remediation
View remediation
