T06 · System Persistence
- Location
SKILL.md:717- Finding
Persistent Cron Installation Replaces the User's Existing Crontab
- Content
View full analysis
/dev/null | openssl x509 -checkend 604800 -noout || echo "CERT EXPIRES WITHIN 7 DAYS" | mail -s "SSL ALERT" admin@example.com' | crontab - ``` ### Technical Analysis The command installs a weekly cron task that survives the current Skill invocation and subsequent Agent sessions. Persistent monitoring is not required to resolve an expired certificate, so this behavior exceeds the minimum privileges and duration required for the Skill's immediate recovery function. Piping a single entry directly into `crontab -` also replaces the executing user's entire existing crontab rather than safely adding an entry. Existing backup, maintenance, security, or monitoring jobs may consequently be removed. Although the supplied payload only performs a TLS certificate check and sends a fixed warning, the scheduled command creates a persistent execution mechanism. Any unreviewed modification to its hostname, recipient, or command body before installation would subsequently execute on a recurring basis with the user's privileges. ### Attack Path 1. An operator invokes the Skill to address a certificate incident. 2. The operator follows the “PREVENTION” instruction and copies the cron command. 3. `crontab -` replaces the user's current cron configuration with the supplied entry. 4. The command persists after the rescue operation and runs every Monday at 09:00. 5. Existing cron entries are lost, and any modified command body gains recurring execution under the affected account. ### Impact Assessment The scheduled task obtains recurring command execution with all privileges available to the user who installs it. If installed from a privileged account, the scope may include privileged system resources. The immediate documented ...[truncated 171 chars]- Remediation
View remediation
/dev/null printf '%s\n' '0 9 * * 1 ...' ) | crontab - ``` - Check for duplicate entries before appending. - Validate and quote all configurable hostnames and email recipients. - Prefer a dedicated, least-privileged monitoring service or scoped systemd timer with auditable configuration. - Include an explicit removal procedure and verify the resulting configuration with `crontab -l`. ]]>
