Resumen de Amenazas por Nivel de Riesgo
2
Crítico
8
Alto
8
Medio
0
Bajo
18 amenazas identificadas en 4 componentes DFD. Las 2 críticas requieren mitigación propietaria antes del despliegue a clientes enterprise.
Secretos Hardcodeados Detectados
Crítico
3
Alto
5
Medio
0
Bajo
1
9 hallazgos en 2 archivos fuente. AWS Access Key, Stripe Live Key y conexión PostgreSQL con contraseña en claro detectadas en
config.js.
Componente: User Authentication 7 amenazas
| STRIDE | Amenaza | Riesgo | DREAD | Vector de Ataque | Mitigaciones |
|---|---|---|---|---|---|
| Spoofing |
Credential Theft
Attacker obtains valid credentials through phishing or theft
|
● Critical |
8.2
D 10 R 8 E 8 A 8 Dc 7 |
Phishing emails, keyloggers, credential stuffing |
|
| Tampering |
JWT Token Manipulation
Attacker modifies JWT claims or signature
|
● High |
6.6
D 10 R 5 E 6 A 5 Dc 7 |
Algorithm confusion, weak secrets, none algorithm |
|
| Spoofing |
Session Hijacking
Attacker steals or predicts session tokens
|
● High | 6.2 |
XSS, network sniffing, session fixation |
|
| DoS |
Authentication Brute Force
Attacker overwhelms authentication service
|
● High | 6.8 |
Distributed credential stuffing, password spraying |
|
| Info Disc. |
Password Hash Exposure
Password hashes leaked through breach or injection
|
● Medium | 6.2 |
SQL injection, backup exposure, insider threat |
|
| Elevation |
Privilege Escalation via Auth Bypass
Attacker gains admin access through auth flaws
|
● Medium | 6.2 |
IDOR, insecure direct object references, role confusion |
|
| Repudiation |
Authentication Event Denial
User denies performing authentication actions
|
● Medium | 4.8 |
Claim of compromised credentials |
|
Resumen por Componente DFD todos los componentes
| Componente | Total | Crítico | Alto | Medio | Bajo | Amenaza Principal | DREAD Máx |
|---|---|---|---|---|---|---|---|
| User Authentication | 7 | 1 | 3 | 3 | 0 | Credential Theft — Spoofing | 8.2 |
| REST API Gateway | 6 | 0 | 3 | 3 | 0 | API Key Impersonation — Spoofing | 7.2 |
| Database (PostgreSQL) | 3 | 0 | 1 | 2 | 0 | SQL Injection — Tampering | 6.8 |
| Storage (S3 / Grabaciones) | 2 | 0 | 1 | 1 | 0 | Insecure File Upload — Info Disclosure | 6.4 |
Matriz STRIDE por Elemento DFD
| Elemento DFD | S — Spoofing | T — Tampering | R — Repudiation | I — Info Disc. | D — DoS | E — Elevation |
|---|---|---|---|---|---|---|
| External Entity (Vendedor) | ✓ | — | ✓ | — | — | — |
| Proceso: Auth Service | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Proceso: API Gateway | ✓ | ✓ | — | ✓ | ✓ | — |
| Data Store: PostgreSQL | — | ✓ | ✓ | ✓ | ✓ | — |
| Data Store: S3 Storage | — | ✓ | — | ✓ | — | — |
| Flujo: JWT Token | — | ✓ | — | ✓ | ✓ | — |
Secretos Detectados en Código Fuente 9 hallazgos — merge bloqueado
CRÍTICO
AWS Access Key ID
config.js:26 · [AWS001]
AKIAY...
AKIAY8X3MWPQZ4RNLK7T
AKIAY8X3MWPQZ4RNLK7T
Usar IAM roles o AWS Secrets Manager — Rotar esta key de inmediato
CRÍTICO
Stripe API Key (LIVE)
config.js:46 · [STRIPE001]
sk_live_51...VwXyZ
Revocar en dashboard Stripe ahora — Usar variables de entorno
CRÍTICO
Database Connection String
config.js:14 · [GEN004]
postgres:/...:5432
con contraseña en claro
con contraseña en claro
Mover a DATABASE_URL env var — Rotar contraseña DB
ALTO
Generic Secret (JWT Secret)
auth.py:8 · [GEN002]
SECRET = "...hare"
Mover a JWT_SECRET env var — Usar firma asimétrica RS256
ALTO
Generic Secret (GitHub Token)
auth.py:11 · [GEN002]
TOKEN = "g...s7oR"
Revocar en GitHub Settings — Usar GitHub App authentication
ALTO
JSON Web Token (hardcoded)
config.js:54 · [JWT001]
eyJhbGciOi...ghere
Nunca hardcodear JWTs — Generar dinámicamente siempre
ALTO
Generic API Key (OpenAI)
config.js:34 · [GEN001]
api_key: '...qAe6'
Revocar en OpenAI Platform — Usar OPENAI_API_KEY env var
ALTO
Generic Secret (JWT secret duplicado)
config.js:40 · [GEN002]
secret: 'l...hare'
Consolidar JWT config — Usar JWT_SECRET de env vars
BAJO
TODO with Secret
auth.py:7 · [LOW001]
# TODO: FI...ecret
Resolver el TODO antes del deploy — Convertir en ticket de backlog
Gate de Verificacion antes del Merge
| Check | Criterio | Estado | Accion requerida |
|---|---|---|---|
| Cobertura STRIDE | Cada elemento DFD tiene ≥1 fila STRIDE considerada | ✓ PASS | 6/6 elementos DFD cubiertos |
| DREAD ≥ 7 con owner | Cada amenaza con DREAD promedio ≥7 tiene owner nombrado | ✗ FAIL | Credential Theft (8.2) sin owner asignado — asignar a equipo backend |
| Secret Scan: zero critical/high | El escaneo de secretos sale con 0 hallazgos críticos o altos | ✗ FAIL | 8 hallazgos activos (3 críticos, 5 altos) — rotar y mover a env vars |
| Re-run post-mitigación | Ambas herramientas re-ejecutadas tras aplicar mitigaciones | — PENDIENTE | Re-ejecutar tras limpiar secretos y aplicar parches |