AutoAddPolicy in Paramiko Disables Host Key Verification and Risks Credential Leakage After IP Reassignment
A developer maintained fourteen separate scripts that performed deployment, service restarts, DNS changes, and mail diagnostics against a production VPS. Each script contained its own copy of the target IP address, a classic copy-paste pattern that survived until the provider migrated the instance.
After the move the old address was promptly reassigned to another customer. Instead of fourteen connection timeouts, every script established an SSH session to the new owner’s server and transmitted the root password stored in the environment variable VPS_PASS.
What AutoAddPolicy Actually Does
When an SSH client connects, the server presents its host key. The client compares this key against entries in known_hosts. A mismatch normally produces the warning “REMOTE HOST IDENTIFICATION HAS CHANGED!” and aborts the session. AutoAddPolicy replaces this check with an unconditional acceptance of any key, eliminating both the warning and the protection.
The policy is often described only as defense against man-in-the-middle attacks. In cloud environments the more immediate risk is simple IP reassignment: the provider reclaims the address and hands it to the next tenant without malice or interception.
Three Required Fixes
- Load system and user host keys explicitly and enforce RejectPolicy so that an unknown or changed key raises an exception before any credentials are sent.
- Store the target address in a single shared module (vps.py) imported by all scripts, eliminating the possibility of fourteen stale copies.
- Prefer key-based authentication; fall back to password only when no key file exists. The private key never leaves the client, so even an unintended connection yields nothing usable to the recipient.
The same trust problem appears when a web service fetches user-supplied URLs. The author’s checker therefore restricts requests to http and https, resolves names before connecting, rejects private, loopback, and link-local ranges, and re-validates after every redirect.
Smoke tests confirm that attempts to reach 127.0.0.1, 169.254.169.254, and file:///etc/passwd are blocked. The incident shows that disabling host-key verification is not a harmless convenience; it is the removal of a control that becomes critical the moment an IP address changes ownership.
Related articles
Developer Exposes 12 Vulnerabilities in FastAPI Todo App After 176 Bots Bypass Protections
A developer building a student-focused todo planner on FastAPI discovered that 176 of 238 new accounts were bots that bypassed three layers of protection including rate limiting and email verification. The issues stemmed from in-memory counters reset on every deployment, uvicorn trusting any X-Forwarded-For header, and email verification never being enforced in code. A full audit revealed additional flaws such as stored XSS via JSON-LD on public Q&A pages and an IDOR allowing any authenticated user to read all tasks in a project by supplying its ID. Fixes included moving rate limits to the database, properly extracting the client IP from the rightmost X-Forwarded-For entry, adding signed form timestamps, and escaping JSON for script contexts. The case highlights common pitfalls when deploying Python web services behind nginx without strict trust boundaries.
Researcher Achieves SSTI-Based Defacement of First Partner Bank Web Service on Standoff 365
A security researcher known as grizzzer detailed a full attack chain that resulted in defacing the authorization page of the First Partner Bank digital banking service inside the Standoff 365 online polygon. The demonstration began with a successful DNS zone transfer against the fpb.stf domain, revealing the dbo.fpb.stf host that hosted the target application. After identifying the Node.js, Express, and React stack, the researcher discovered that the receipt generation endpoint accepted an undocumented pretty parameter that was passed directly into the Pug template engine. This led to a server-side template injection vulnerability that was escalated to a Node.js reverse shell. With code execution, the attacker located and modified the translation.json localization file, replacing the welcome message with the string pwned by VON visible to all users. The write-up concludes with concrete hardening recommendations including disabling zone transfers, avoiding direct spread of req.query into templates, and restricting outbound connections.
Telegram Desktop Bug Deletes 800 GB of User Data Due to Spelling Checker Path Error
A Telegram Desktop update introduced a critical flaw that caused the application to recursively delete user folders containing up to 800 GB of data on Windows systems. The root cause traced back to an incorrect path construction for the custom dictionary file used by the lib_spellcheck library when Windows native spell checking was enabled. Due to a misplaced return statement in the code, the working directory path remained empty, leading Qt to interpret the path as the root-level C:\custom folder. The application then invoked QDir::removeRecursively on this directory, removing all accessible files while skipping locked ones. The bug affected releases 7.1.0 and 7.1.1 for approximately 66 hours before being fixed in version 7.1.2. Researchers used Process Monitor to confirm Telegram.exe was directly responsible for the deletion attempts. The incident highlights risks of combining recursive deletion functions with unvalidated path inputs in widely used applications.
WatchGuard Issues Emergency Patches for Fireware OS Addressing 11 Vulnerabilities Including Pre-Auth RCE
WatchGuard Technologies released security updates for its Firebox firewall products on August 27, 2026, addressing 11 vulnerabilities in Fireware OS. Nine of the flaws affect the IKE daemon (iked) and can lead to buffer overflows, out-of-bounds reads, and double-free conditions when processing crafted IKE messages. Three CVEs (CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318) may allow unauthenticated remote code execution due to memory corruption, with CVE-2026-19318 requiring the IKE payload diagnostic log to be enabled. An additional flaw, CVE-2026-13086, resides in the deprecated Mobile Security epm service and permits adjacent-network attackers with access to a trusted interface to execute arbitrary code as root without authentication. The company urges immediate application of Fireware versions 2026.2.2, 12.12.2, and 12.5.20.