T06 · System Persistence
- Location
references/shell-oneliners.md:178- Finding
Persistent System-Wide Login Hook Can Terminate SSH Sessions
- Content
View full analysis
/etc/profile << __EOF__ _after_logout() { username=$(whoami) for _pid in $(ps afx | grep sshd | grep "$username" | awk '{print $1}') ; do kill -9 $_pid done } trap _after_logout EXIT __EOF__ ``` ### Technical Analysis The command overwrites `/etc/profile`, a system-wide configuration file evaluated by login shells. It installs an `EXIT` trap that searches for SSH processes matching the current username and terminates them using `SIGKILL`. This behavior exceeds the minimum privileges required by a sysadmin command-reference Skill. It requires elevated write access to `/etc/profile`, modifies behavior across future sessions, and does not preserve the existing profile. The process selection pipeline is also imprecise: textual matching through `ps`, `grep`, and a username can select unrelated or administratively important processes. The modification persists after the originating command or Skill interaction ends. There is no backup, confirmation, ownership validation, rollback procedure, or warning about its system-wide scope. ### Attack Path 1. A user asks a general shell or SSH administration question, causing the Skill to auto-consult the command reference. 2. The profile-modification recipe is returned or recommended without an explicit production-safety boundary. 3. A privileged user executes the command. 4. The existing `/etc/profile` is replaced with attacker-influenced or unsafe content. 5. Future login shells install the exit trap. 6. When a shell exits, matching SSH processes are forcibly terminated. 7. Administrators or users may lose active sessions, and the behavior continues until `/etc/profile` is repaired. ### Impact Assessment Successful use can obtain persistent control o ...[truncated 528 chars]- Remediation
View remediation
