celvexgroup commited on
Commit
4c9ca2e
·
verified ·
1 Parent(s): fa976ab

Upload README.md with huggingface_hub

Browse files
Files changed (1) hide show
  1. README.md +10 -0
README.md ADDED
@@ -0,0 +1,10 @@
 
 
 
 
 
 
 
 
 
 
 
1
+ # PoC - modelaudit llamafile scanner /dev/tcp fileless-C2 blind spot (BL-0116)
2
+
3
+ Coordinated disclosure PoC for huntr (Protect AI MFV). Benign, localhost-only markers.
4
+
5
+ - Scanner: modelaudit==0.2.49 (llamafile_scanner.py). Format: Llamafile (.llamafile, an APE polyglot executable + GGUF).
6
+ - `modelaudit scan evasion_devtcp_revshell.llamafile` -> Clean / exit 0: the APE shell stub establishes C2 via bash `/dev/tcp` (the canonical fileless reverse-shell primitive), which produces neither a command nor a network signal, because the scanner's NETWORK_TOKENS list omits /dev/tcp and /dev/udp. The byte-equivalent intent as `curl ... | sh` (control_curl_pipe_sh.llamafile) is correctly flagged CRITICAL - positive control. `nc -e` reverse shells are missed the same way.
7
+ - Root cause: llamafile_scanner.py:389-395 NETWORK_TOKENS omits /dev/tcp,/dev/udp; :362-372 command indicators miss socket-FD shells; :3055-3066 _runtime_text_signals returns (False,False) -> no finding.
8
+ - Benign: the stub connects to 127.0.0.1 only and sends a marker; no external egress. Distinct from GGUF findings (this is the executable-stub runtime analysis, not the embedded model).
9
+
10
+ Files: evasion_devtcp_revshell / evasion_devtcp_exfil / evasion_nc_revshell (bypass), control_curl_pipe_sh / control_bash_dash_c (fire), baseline_clean (true-negative). Full report in huntr submission.