Hardcoded IP Addresses and Hostnames

Detects internal IP addresses, localhost references, and hardcoded hostnames that indicate misconfiguration or information disclosure.

zakirkun Updated

File contents

Hardcoded IP Addresses and Hostnames

Overview

Hardcoded IP addresses and internal hostnames in source code can:

  • Expose internal network topology to attackers who gain code access
  • Prevent deployment flexibility (tied to a specific environment)
  • Point to services with weaker security than production (dev/staging servers)
  • Enable SSRF if an attacker can influence which IP is connected to

Detection Strategy

  • Internal IP ranges: 10.x.x.x, 172.16-31.x.x, 192.168.x.x
  • Localhost with non-standard ports: 127.0.0.1:8080
  • Cloud provider metadata endpoints: 169.254.169.254
  • Hardcoded database hostnames in non-config files

Remediation

Move all hostnames and IPs to environment variables or configuration files that are not committed to source control.

zakirkun/ice-tea/tree/main/skills/infra/hardcoded-ips commit 50f0f67212

Frequently asked questions

npx skillmds@latest add zakirkun/hardcoded-ip-addresses-and-hostnames