T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/daemon.py:777- Finding
Unauthenticated Loopback Interface Allows Unauthorized Trading Operations
- Content
View full analysis
None: srv = socket.socket(socket.AF_INET, socket.SOCK_STREAM) srv.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1) srv.bind(("127.0.0.1", port)) srv.listen(5) srv.settimeout(1.0) logger.info("命令监听端口: %d", port) while self._running: try: conn, _ = srv.accept() except socket.timeout: continue threading.Thread(target=self._handle_conn, args=(conn,), daemon=True).start() srv.close() def _handle_conn(self, conn: socket.socket) -> None: try: data = b"" while True: chunk = conn.recv(4096) if not chunk: break data += chunk if b"\n" in data: break cmd = json.loads(data.decode()) resp = self._handle_cmd(cmd) conn.sendall((json.dumps(resp, ensure_ascii=False) + "\n").encode()) except Exception as e: try: conn.sendall((json.dumps({"ok": False, "error": str(e)}) + "\n").encode()) except Exception: pass finally: conn.close() ``` The account check is optional because it only rejects a request when an `account_id` is supplied and does not match: ```python def _handle_cmd(self, cmd: dict) -> dict: """Dispatch a command, journaling every state-changing request.""" target_account = str(cmd.get("account_id") or "").strip() if target_account and target_account != self.account_id: return { ...[truncated 4963 chars]- Remediation
View remediation
