T06 · System Persistence
- Location
SKILL.md:152- Finding
Recurring Calendar Synchronization Creates Cross-Session System Persistence
- Content
View full analysis
> /var/log/dingtalk_sync.log 2>&1 ``` ### Technical Analysis The documented configuration establishes a cron task that executes three times every day and survives the original Skill session. Scheduled synchronization is related to the declared functionality and is disclosed to the user, but it is not necessary for one-time or manually initiated synchronization. The scheduled process repeatedly receives access to locally stored DingTalk application credentials, Feishu application credentials and tokens, calendar contents, and Feishu event creation and deletion capabilities. The use of `/root` paths and a system log also suggests execution in a highly privileged account, although the documentation does not explicitly require that cron itself run as root. ### Attack Path 1. A user follows the scheduling instructions and edits their crontab. 2. The synchronization script is registered to run at 09:00, 12:00, and 15:00 every day. 3. The task persists beyond the setup session and runs without renewed user approval. 4. Each execution reads stored credentials, retrieves private calendar data, refreshes tokens, deletes selected Feishu events, and creates replacement events. 5. Any existing defect or later unauthorized modification to the script is consequently executed on every schedule. ### Impact Assessment The persistent task can repeatedly exercise all privileges granted to the DingTalk and Feishu applications, including reading private schedules and modifying the configured Feishu calendar. If configured under a privileged account, compromise of the script or its writable dependencies could also result in rec ...[truncated 57 chars]- Remediation
View remediation
