T09 · Insecure Skill Coding Practices
- Location
references/proxy-pool-setup.md:72- Finding
Persistent Internet-Facing SOCKS5 Proxy Uses Publicly Documented Credentials
- Content
View full analysis
/etc/danted.conf << 'DANTE_EOF' internal: eth0 port = 1080 external: eth0 socksmethod: username client pass { from: 0.0.0.0/0 to: 0.0.0.0/0 log: connect disconnect error } socks pass { from: 0.0.0.0/0 to: 0.0.0.0/0 command: bind connect udpassociate log: connect disconnect error } DANTE_EOF echo "=== Creating authentication user ===" useradd -r -s /bin/false dante_proxy 2>/dev/null || true echo "dante_proxy:ChangeThisPassword123" | chpasswd systemctl restart danted systemctl enable danted if systemctl is-active --quiet danted; then echo "Dante is running" else echo "Dante failed to start" fi echo "" echo "SOCKS5 proxy information:" echo " Address: $(curl -s ifconfig.me)" echo " Port: 1080" echo " User: dante_proxy" echo " Password: ChangeThisPassword123" ``` ### Technical Analysis The root-level deployment script exposes Dante on `eth0:1080`, accepts clients from `0.0.0.0/0`, permits arbitrary destinations, and installs a fixed password published directly in the repository. It then enables the service through `systemctl`, causing the proxy to survive reboots. Service persistence is functionally consistent with operating an always-on proxy and is not evidence of a hidden backdoor by itself. However, the persistent service is deployed before mandatory source restrictions are enforced. The later firewall guidance only recommends source-IP filtering and therefore does not safely constrain the configuration shown above. The use of a known password also means that network reachability effectively provides access to the proxy. Printing the credentials to the terminal can additionally expose them through terminal logs or operational records. ### At ...[truncated 923 chars]- Remediation
View remediation
