T06 · System Persistence
- Location
setup.sh:73- Finding
Default Installation Creates a Persistent Scheduled Task
- Content
View full analysis
"$NIGHTLY_SCRIPT" << 'SCRIPT' #!/bin/bash # Nightly memory processing DATE=$(date +%Y-%m-%d) echo "Processing: $DATE" >> ./Memory/Processing/Nightly/logs/"$DATE".md # Add your processing logic here SCRIPT chmod +x "$NIGHTLY_SCRIPT" mkdir -p "$VAULT_DEST/Memory/Processing/Nightly/logs" # Add to crontab (03:00 MSK daily) (crontab -l 2>/dev/null | grep -v "AB-Memory-Vault"; echo "0 3 * * * cd $VAULT_DEST && bash $NIGHTLY_SCRIPT >> $VAULT_DEST/Memory/Processing/Nightly/logs/\$(date +\%Y-\%m-\%d).log 2>&1") | crontab - echo -e " ${CRAB}✓${NC} Cron installed (03:00 MSK daily)" fi ``` ### Technical Analysis The primary installer modifies the current user's crontab unless the user explicitly supplies `--skip-cron`. This creates a scheduled execution mechanism that survives completion of the installation and subsequent login sessions. Nightly processing is an advertised feature, so scheduling can be legitimate when explicitly requested. However, the implementation exceeds minimum necessary privileges because persistence is enabled by default and the installed processor currently performs no memory processing beyond appending a date to log files. The executable is also stored inside the user-facing vault rather than in a protected application directory. Any actor or process capable of replacing or editing `Memory/Processing/Nightly/process.sh` can cause arbitrary command ...[truncated 1449 chars]- Remediation
View remediation
