T03 · Remote Payload Retrieval and Execution
- Location
BitSoulFaceBeautySkill/init.py:31- Finding
Unsigned Remote Native Binary Download and Execution
- Content
View full analysis
str: url = f"{BASE_URL}/api/download_file" params = { "file_name": file_name, "token_key": token_key } try: response = requests.get(url, params=params) if response.status_code == 200: data = response.json() download_url = data.get("download_url", "") return download_url else: return "" except Exception as e: print(f"request_download_url error: {e}") return "" def download_data_file(file_name: str, output_path: str, max_retries: int = 3) -> bool: token = get_token() if not token: print("Error: No token set, cannot download data file.") return False for retry in range(max_retries): try: download_url = request_download_url(file_name, token) if not download_url: print(f"Error: Failed to get download url for {file_name}, please check if your token is valid.") return False print(f"Starting to download {file_name} ...") print(f"Download url: {download_url}") with requests.get(download_url, stream=True, timeout=300) as response: if response.status_code != 200: print(f"Download failed, HTTP status code: {response.status_code}") if retry < max_retries - 1: print(f"Retrying {retry + 1}/{max_retries} ...") continue return False total_size = int(response.headers.get('content-length', 0)) downloaded = 0 chunk_size ...[truncated 4899 chars]- Remediation
View remediation
