T05 · Unauthorized Access and Privilege Escalation
- Location
references/clawhub-publishing.md:69- Finding
Private SSH Key and Authentication Token Cloning
- Content
View full analysis
~/.ssh/config << 'EOF' Host github.com HostName github.com User git IdentityFile ~/.ssh/id_ed25519_backup IdentitiesOnly yes EOF ssh -T git@github.com # Import the ClawHub token from the remote server scp root@43.173.120.234:~/.config/clawhub/config.json ~/.config/clawhub/config.json clawhub whoami ``` ```bash # references/cross-server-deployment.md scp root@SOURCE_IP:~/.config/clawhub/config.json ~/.config/clawhub/config.json clawhub whoami scp root@SOURCE_IP:~/.ssh/id_ed25519 ~/.ssh/id_ed25519_backup cat >> ~/.ssh/config << 'EOF' Host github.com HostName github.com User git IdentityFile ~/.ssh/id_ed25519_backup IdentitiesOnly yes EOF ssh -T git@github.com ``` ### Technical Analysis The deployment guides instruct users or Agents to copy an existing account's private SSH key and ClawHub authentication configuration to another machine. A private key and bearer token are identity-bearing credentials; copying them duplicates the original identity rather than establishing a new, independently revocable identity for the destination. This behavior is not necessary for the declared DAG workflow functionality. Even for publishing and deployment, a unique per-host SSH key and a new scoped ClawHub token are sufficient and materially safer. The examples also retrieve the secrets through a privileged `root` account and do not explicitly enforce restrictive permissions on the copied files. ### Attack Path 1. A user requests publishing or cross-server deployment. 2. The Agent follows the referenced instructions. 3. The Agent connects t ...[truncated 880 chars]- Remediation
View remediation
