T09 · Insecure Skill Coding Practices
- Location
scripts/login.py:16- Finding
TLS Certificate Verification Is Disabled for Authentication Requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/login.py, lines 4-6, 16-27, and 100-104
Vulnerability Type: Improper certificate validation
Risk Level: CriticalVulnerable Code
python import urllib3 urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) requests.packages.urllib3.disable_warnings()python def __init__(self, base_url="http://your-backend-url"): self.base_url = base_url self.session = requests.Session() self.session.verify = False def get_public_key(self, account): """Get RSA public key""" url = f"{self.base_url}/api/v1/SysUser/GenerateEncryptKey" params = {"userName": account} response = self.session.get(url, params=params, verify=False) response.raise_for_status()python print(f"Logging in with account: {account}") response = self.session.post(url, json=login_data, verify=False) response.raise_for_status()The configured endpoint is also a bare IP address:
json { "baseUrl": "https://36.139.200.220:8081" }Technical Analysis
The client disables TLS certificate verification at both the session and individual-request levels. It also suppresses the warnings that would normally reveal this unsafe behavior. Consequently, HTTPS provides encryption without reliable server authentication.
This is particularly dangerous in the login flow because the client first downloads an RSA public key from the unverified endpoint and then encrypts the user's password with that key. RSA encryption does not protect the password if an attacker can replace the public key. A man-in-the-middle attacker can provide an attacker-controlled certificate and public key, allowing the attacker to decrypt the submitted password.
The same attacker can modify the authentication response, including the returned access token. This compounds the command-injection risk described separately.
Base64 encoding o ...[truncated 1449 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
self.session.verify = Falseand everyverify=Falseargument. - Remove the suppression of
InsecureRequestWarning. - Configure the service with a DNS hostname covered by a valid certificate from a trusted certificate authority.
- If a private certificate authority is necessary, provide its CA bundle explicitly:
python session.verify = "/secure/path/to/private-ca.pem" - Do not implement a fallback that retries with verification disabled.
- Consider certificate or public-key pinning if the deployment model requires additional protection, while maintaining a secure key-rotation procedure.
- Validate the schema and expected cryptographic properties of the public-key response before using it.
- Add automated tests confirming that invalid, expired, mismatched, and untrusted certificates cause authentication to fail closed.
- Remove
