Repository navigation
Send X-Agent headers with requests to Aikido - #516
Conversation
| func setAgentHeaders(req *http.Request, server *ServerData) { | ||
| req.Header.Set("X-Agent-Platform", "php") | ||
| req.Header.Set("X-Agent-Library", "firewall-php") | ||
| req.Header.Set("X-Agent-Version", constants.Version) | ||
| req.Header.Set("X-Agent-Hostname", cmp.Or(globals.Machine.HostName, "unknown")) | ||
| req.Header.Set("X-Agent-IP-Address", cmp.Or(globals.Machine.IPAddress, "unknown")) | ||
| req.Header.Set("X-Agent-Session-Id", server.SessionID) | ||
| } |
There was a problem hiding this comment.
🔵 Low - Redirects disclose the new agent identity headers cross-host
When either configured Aikido endpoint returns a redirect to another host, the default HTTP clients follow it and retain these newly added X-Agent headers. The redirect destination can therefore receive the machine hostname, local IP address, and stable session identifier even though Go normally removes the Authorization header on a cross-host redirect.
Show fix
Disable cross-host redirects for cloud requests, or validate the final host and remove the X-Agent headers before following a redirect to a different origin.
More info - Reply on this comment to give feedback or ignore the issue.
c762f94 to
bf39156
Compare
| // The custom Go toolchain we use for Alpine has no uuid package | ||
| func newSessionID() string { | ||
| var b [16]byte | ||
| rand.Read(b[:]) |
There was a problem hiding this comment.
🔵 Low - Entropy failures produce colliding session IDs
If the system crypto source returns an error or partial read while a new ServerData is created, newSessionID ignores that failure and still returns an ID. The timestamp bytes are filled afterward but the random suffix can remain zero or partially filled, so sessions created in the same millisecond can share an identifier and be mis-correlated by the cloud.
Show fix
Check and propagate the error from crypto/rand.Read; do not create or transmit a session ID unless its random bytes were fully generated, or use a documented collision-safe fallback that preserves session separation.
More info - Reply on this comment to give feedback or ignore the issue.
bf39156 to
eac0069
Compare
| func newSessionID() string { | ||
| var b [16]byte | ||
| if _, err := rand.Read(b[:]); err != nil { | ||
| return "unknown" |
There was a problem hiding this comment.
Not reachable but fine to keep idiomatic go error checking
No description provided.