http_check.py allows opening local files via file://localhost/... URLs
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 1.9k
- Forks
- 191
- Avg merge
- 36m
- Merged PRs (30d)
- 12
Description
http_check.py is intended to check HTTP/HTTPS headers (Gzip, ETag, Last-Modified). However, it does not validate the URL scheme, and urllib.request.urlopen handles file: URLs by default.
While file:///etc/passwd is rejected due to a missing netloc, passing file://localhost/... bypasses the check and causes the script to open and read local files.
Example input: python3 python/http_check.py "file://localhost/etc/passwd"
Expected behavior: The script should only accept http:// and https:// URLs and reject other schemes.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with python/http_check.py and inspect how URLs are parsed before urllib.request.urlopen is called. Run the reported file://localhost/etc/passwd example and verify that non-HTTP(S) schemes are rejected while HTTP and HTTPS header checks continue to work.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- cli, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 82/100