T03 · Remote Payload Retrieval and Execution
- Location
scripts/download_media.sh:78- Finding
Unverified Remote Executable Retrieval and Execution in Single-Media Downloader
- Content
View full analysis
/dev/null; then if [ -f "$HOME/yt-dlp" ]; then YT_DLP="$HOME/yt-dlp" else echo "Installing yt-dlp to ~/yt-dlp..." curl -L https://github.com/yt-dlp/yt-dlp/releases/latest/download/yt-dlp -o "$HOME/yt-dlp" chmod +x "$HOME/yt-dlp" YT_DLP="$HOME/yt-dlp" fi else YT_DLP="yt-dlp" fi # Check if ffmpeg exists (needed for MP3 conversion) if ! command -v ffmpeg &> /dev/null; then if [ -f "$HOME/ffmpeg-portable/bin/ffmpeg" ]; then FFMPEG_PATH="$HOME/ffmpeg-portable/bin" echo "Using existing ffmpeg at $FFMPEG_PATH" else echo "Installing ffmpeg for audio conversion..." mkdir -p "$HOME/ffmpeg-portable" cd "$HOME/ffmpeg-portable" curl -L https://github.com/BtbN/FFmpeg-Builds/releases/download/latest/ffmpeg-master-latest-linux64-gpl.tar.xz -o ffmpeg.tar.xz tar -xf ffmpeg.tar.xz --strip-components=1 rm -f ffmpeg.tar.xz cd - > /dev/null FFMPEG_PATH="$HOME/ffmpeg-portable/bin" echo "ffmpeg installed to $FFMPEG_PATH" fi export PATH="$FFMPEG_PATH:$PATH" else echo "Using system ffmpeg" fi ``` The downloaded `yt-dlp` executable is subsequently invoked at `scripts/download_media.sh:135-141` or `scripts/download_media.sh:171-175`. FFmpeg is invoked indirectly by `yt-dlp` during audio extraction. ### Technical Analysis The script automatically downloads executable dependencies through mutable `latest` release URLs. It neither pins an immutable release version nor verifies a cryptographic checksum or publisher signature before making the downloaded `yt-dlp` file executable and running it. The FFmpeg archive is also downloaded from BtbN, a third ...[truncated 2386 chars]- Remediation
View remediation
