Description
Sending sensitive data through an unprotected socket lets someone observing the network read it.
Potential impact
- Passwords, tokens and personal information can be intercepted or reused.
Remediation
Use a protected channel such as TLS with peer-certificate and hostname verification. Stop transmission if verification fails, and do not fall back to plaintext.
Examples
Before
c
const char *password = getenv("PASSWORD");
send(fd, password, strlen(password), 0);
After
c
const char *password = getenv("PASSWORD");
SSL_write(ssl, password, strlen(password));
The first excerpt sends a password directly through an unprotected socket. The second uses the TLS connection's write API. The certificate and hostname verification settings for ssl, and connection establishment, are omitted. Check that the environment variable exists and its length is appropriate; handle the SSL_write return value, retries and errors too.