Skip to main content

Crate persistence

Crate persistence 

Source
Expand description

Where Linux and Unix attackers keep access to a host: crontabs, at jobs, systemd units, init scripts, SSH authorized keys and the SSH server’s configuration, rc.local and shell start-up files, /etc/ld.so.preload, sudoers and PAM, read from the host files of a triage collection.

detect tells a file’s Kind from its path on the host (etc/crontab, home/alice/.ssh/authorized_keys, [root]/etc/sudoers, …), and parse reads it into Entrys: one per job, setting, key, command line, library or rule, with the line it’s on, the account it runs as or belongs to, what it runs and when. flags lists the traits that look like an attacker’s (Flag).

Lines that can’t be read are reported in problems, never fatal; no input makes these functions panic.

use persistence::{detect, flags, parse, Flag};

let path = "[root]/etc/cron.d/sysupdate";
let kind = detect(path).unwrap();
let parsed = parse(kind, b"@reboot root /dev/shm/.x/run\n", path);
let job = &parsed.entries[0];
assert_eq!(job.summary(), "@reboot as root: /dev/shm/.x/run");
assert_eq!(flags(job), [Flag::TemporaryDirectory, Flag::AtReboot]);

Structs§

AuthorizedKey
A key that may log in.
Entry
One job, setting, key, command line, library or rule.
KeyOption
An option before a key: no-pty, or from="198.51.100.0/24".
PamRule
A PAM rule: type control module arguments.
Parsed
A file’s entries.
SudoRule
A sudoers rule: users hosts = (run-as) TAGS: commands.

Enums§

Detail
What else a line holds, by what it is.
Flag
A suspicious trait.
Kind
A kind of file, each read its own way.

Constants§

VERSION
This crate’s version, for records of what parsed them.

Functions§

detect
A file’s kind from its path on the host: relative to the root (etc/crontab), absolute (/etc/crontab), or as a collection stores it ([root]/etc/crontab, uac/[root]/etc/crontab); / or \ separated. None for files this crate doesn’t read.
flags
What looks suspicious about entry, in Flag order.
parse
Read a file of kind found at path on the host. The path names the account for users’ crontabs, keys, start-up files and units.