T06 · System Persistence
- Location
scripts/setup_keepalive.sh:27- Finding
Persistent scheduled execution through user crontab modification
- Content
View full analysis
> /tmp/xiaohongshu_keepalive.log 2>&1" if crontab -l 2>/dev/null | grep -q "login_keeper.py"; then read -p "> " replace if [ "$replace" = "y" ]; then (crontab -l 2>/dev/null | grep -v "login_keeper.py"; echo "$CRON_CMD") | crontab - fi else (crontab -l 2>/dev/null; echo "$CRON_CMD") | crontab - fi crontab -l | grep login_keeper.py ``` ### Technical Analysis The setup script modifies the current user's crontab to execute `login_keeper.py` every 30 minutes. The job survives the original Skill run and continues accessing an authenticated browser profile across future sessions. Session retention is related to the advertised functionality, and installation requires an interactive selection. Nevertheless, scheduled persistence is not required for on-demand publishing and exceeds the minimum privileges needed by the core feature. Both `SKILL.md` and the setup interface strongly recommend this persistent mode rather than presenting it as an exceptional option. The cron command also interpolates `SCRIPT_DIR` without cron-safe shell quoting. Installation from a path containing spaces or shell metacharacters could cause the job to fail or change its interpretation. Existing jobs are detected and removed using the broad substring `login_keeper.py`, which can match unrelated cron entries. ### Attack Path 1. The user follows the recommended login-retention instructions. 2. The user runs `scripts/setup_keepalive.sh` and selects option 1. 3. The script reads the user's existing crontab and appends a recurring entry. 4. Every 30 minutes, cron launches `login_keeper.py`. 5. The recurring process starts or c ...[truncated 804 chars]- Remediation
View remediation
