T03 · Remote Payload Retrieval and Execution
- Location
ocr_setup.py:150- Finding
Downloaded Executables Are Used Without Cryptographic Integrity Verification
- Content
View full analysis
None: """Download and extract the llama.cpp Vulkan prebuilt binary.""" tag = tag or LLAMA_TAG llama_dir = os.path.join(ocr_dir, "llama.cpp") url = ( f"https://github.com/ggml-org/llama.cpp/releases/download/{tag}" f"/llama-{tag}-bin-win-vulkan-x64.zip" ) print(f"Downloading llama.cpp {tag} ...") zip_path = os.path.join(tempfile.gettempdir(), "llama-vulkan.zip") urllib.request.urlretrieve(url, zip_path) os.makedirs(llama_dir, exist_ok=True) with zipfile.ZipFile(zip_path, "r") as zf: zf.extractall(llama_dir) os.remove(zip_path) print("LLAMA_INSTALL=DONE") ``` The extracted executable is subsequently launched by `ocr_run.py`: ```python SERVER_EXE = os.path.join(LLAMA_DIR, "llama-server.exe") server_proc = subprocess.Popen( server_args, stdout=subprocess.PIPE, stderr=subprocess.PIPE, stdin=subprocess.DEVNULL, creationflags=_CREATE_NO_WINDOW, ) ``` The Skill documentation also instructs users to download and execute Miniforge installers without checking a digest or signature: ```powershell $mf = "$env:TEMP\Miniforge3-Windows-x86_64.exe" Invoke-WebRequest -Uri "https://github.com/conda-forge/miniforge/releases/latest/download/Miniforge3-Windows-x86_64.exe" -OutFile $mf Start-Process $mf -ArgumentList "/S /D=$env:USERPROFILE\miniforge3" -Wait Remove-Item $mf ``` ```bash MF_URL="https://github.com/conda-forge/miniforge/releases/latest/download/Miniforge3-Linux-x86_64.sh" MF_INSTALLER="/tmp/Miniforge3-install.sh" curl -fsSL "$MF_URL" -o "$MF_INSTALLER" bash "$MF_INSTALLER" -b -p "$HOME/miniforge3" rm -f "$MF_INSTALLER" ``` ### Technica ...[truncated 2483 chars]- Remediation
View remediation
