6 ms·
Heap-overflowing Llama.cpp to RCE
- rzk 2y agoThis is amazing—made even more impressive by the fact that the author is just 15 years old! Also, it's nice to see this mentioned: > For this 10k-word write-up, I spent around a month finishing up the main parts, and refining/editing it took an extra while. Writing this is indeed a painful process. I spent the entire day on the weekend and 4-5 hours during the rest of the week working on it for around two weeks. It's the kind of behind-the-scenes effort that often goes unspoken.
- Sheeny96 2y ago10k words was the word count for my 3rd year undergraduate dissertation in the UK. Typically, this is tirelessly worked on over months. The quality of this far exceeds anything I produced during that time and anything I saw from my peers.
- deleted 2y ago[deleted]
- asveikau 2y agoI'm also detecting hints of non-native English in his writing which may make it even more effort. Though his Twitter account says he's based in Connecticut. Edit: Wow, shocked that I'm being received so negatively about this, non native English is not "bad". It isn't meant as judgement but praise for what he's accomplished.
- johnisgood 2y agoHe's 15. Many adults whose native language is English can't write it correctly, or what are you referring to if not grammar errors? Can you give me examples?
- asveikau 2y agoThe way grammar works is that it is hard to describe the rules of your native language. I am parsing this as non native. My older kid is a few years younger than this guy, and her text messages to me sound more native than this corpus. No I can't describe it concretely. It's just how I parse word choice and sentence structure.
- johnisgood 2y agoI read it again. I can see where you are coming from though. I didn't downvote you.
- asveikau 2y agoYeah, I removed the first part and made it into an edit of the original comment, since it wasn't directed at you.
- johnisgood 2y agoI know, thank you.
- deleted 2y ago[deleted]
- yamrzou 2y agoI tried to execute the PoC by running the following: git clone https://github.com/ggml-org/llama.cpp.git && cd llama.cpp git checkout c0d4843225eed38903ea71ef302a02fa0b27f048 # Checkout a revision prior to the exploit fix in 1d20e53c40c3cc848ba2b95f5bf7c075eeec8b19 mkdir build-rpc && cd build-rpc cmake .. -DGGML_RPC=ON cmake --build . --config Release cd bin/ ./rpc-server -p 50052 In a second terminal: nc -lvp 1337 Then running the exploit code in a third terminal (from llama.cpp/build-rpc/bin directory): pip install pwntools python exp.py # From https://gist.github.com/retr0reg/d13de3fde8f9d138fe1af48e59e630a9 It failed at Stage Three: Bypass boundary check via libggml and raised an EOFError. The RPC server exited with Segmentation fault. Any idea why?
- retr0reg 2y agoit can be both because of the unsuccessful leak / wrong `libggml-base` offset. We're building a fake `ggml_backend_buffer` table from the leaked base + offset (the hard-coded offset of `libggml-base` should be adjusted with the compiled release) However this exploitation is not actually `libggml-base` version dependent, the partial-writing space is always one byte, and you can leak the `libggml-base` version with after a successful leak if you build every release's `libggml-base`, and map the last-two-bytes with each version. I am happy you read it and liked it; more glad you tried it yourself :D
- VladVladikoff 2y agoThis is really incredible work. And the fact that you are 15 is blowing my mind. You have a really bright future ahead of you, and your parents must be really proud (at least I would be if you were my kid.) Hit me up if you want a summer internship finding security vulnerabilities at a hotel software startup (access control, property management, etc)
- worldsavior 2y ago[flagged]
- ziddoap 2y agoThis is a crazy amount of assumptions to make about someone (and their family) that you know nothing about.
- worldsavior 2y agoYou're right, I don't know anything about his family intially, but it doesn't make me wrong. You can't do the kind of stuff he did without having a lot, a lot of time at hand. I'm not saying he is a problem, but I disagree with the path he has chosen.
- nemothekid 2y ago>without having a lot, a lot of time at hand Of course he has a lot of time at hand. He's a teenager.
- gosub100 2y agoGeohot removed the SIM lock on iPhones when he was 17 https://en.m.wikipedia.org/wiki/George_Hotz https://en.m.wikipedia.org/wiki/George_Hotz Dude rooted the PS3 by directly reading the ram chips ( _from electrical probes _) 2 years later. I don't think his parents helped.
- asveikau 2y agoA lot of us reading your comment were coding at 15.
- om8 2y agoNot surprising, llama.cpp code is a mess. It's sad that hacked things that emerge first are way more popular than properly done projects that come later.
- qskousen 2y agoIs there a comparable open source thing "done properly"?
- deleted 2y ago[deleted]
- tuveson 2y agollama.rs, of course /s
- retr0reg 2y agoIn fact the llama.cpp codebase is well-developed and actively maintained. It has undergone iterative security hardening, intensive low-level security checks have been implemented in both the core inference engine and RPC components. This standard of security is what made the exploitation such challenging and rewarding.
- PartiallyTyped 2y agoThanks for the writeup! Was a very interesting read! I've subscribed and I am looking forward to your next exploits! ^_^
- vlovich123 2y agoIt’s actively maintained but I wouldn’t classify it as a clean codebase. Neither the abstractions it has within ggml, the structure of llama.cpp, effective use of modern c++ etc. it can’t even really make up its mind as to whether it should be c++ or c and there’s a lot of dirt because of that. Heck instead of using a submodule they’re copying ggml between projects making it very difficult to keep track of what’s actually happening where and what the ground truth is. It’s sloppy engineering. Parts are better designed for sure. None of that is meant to take away from your effort or the success of llama.cpp, but I have spent quite a bit of time reading and working with the internals across layers and have a good eye for quality c++ patterns.
- m00dy 2y ago[flagged]
- rboyd 2y agosheesh. the visual aesthetics and script behavior on your blog are so tastefully executed. great job!
- andrewSC 2y agoI'd honestly love to know what framework, theme, or stack is being used here! Looks incredible--great job!
- evannotfound 2y agoHi! I am the developer of Retr0's portfolio. I used nextjs for the framework, with framer motion + gsap for animation. The blog is powered by hashnode headless api with serverside rendering.
- andrewSC 2y agoAwesome! Thank you for the follow up and great work!
- krackers 2y agoThe smudges on the screenshots got me.
- evannotfound 2y agothank you for your support!
- zaphod420 2y agoCan anyone tl/dr this? Does this mean that its possible for a maliciously crafted LLM to execute arbitrary code via an exploit in llama.cpp?
- krackers 2y agoSummary at https://github.com/ggml-org/ggml/pull/1103 https://github.com/ggml-org/ggml/pull/1103
- cadamsdotcom 2y agoThanks for adding value today.
- behnamoh 2y agoprodigies are amazing, but I often wonder what they end up doing later in life when the intelligence gap between them and their peers converges to zero.
- pragmatic8 2y agoWhy do you presume that the intelligence gap would converge to zero?
- ziddoap 2y agoEventually everyone dies, thus becoming equally intelligent!
- behnamoh 2y agoeasy: how many genius people do you know who were also prodigies? early intelligence only gets you so far, the rest depends on hard work, passion, etc.
- FeepingCreature 2y agoIf your later work overshadows your earlier, you're not generally remembered as a prodigy.
- curtisszmania 2y ago[dead]