Expand description
Where Linux and Unix attackers keep access to a host: crontabs, at
jobs, systemd units, init scripts, SSH authorized keys and the SSH
server’s configuration, rc.local and shell start-up files,
/etc/ld.so.preload, sudoers, PAM, udev rules, XDG autostart entries
and kernel modules, read from the host files of a triage collection.
detect tells a file’s Kind from its path on the host
(etc/crontab, home/alice/.ssh/authorized_keys, [root]/etc/sudoers,
…), and parse reads it into Entrys: one per job, setting, key,
command line, library or rule, with the line it’s on, the account it
runs as or belongs to, what it runs and when. flags lists the traits
that look like an attacker’s (Flag).
Lines that can’t be read are reported in problems, never fatal; no
input makes these functions panic.
use persistence::{detect, flags, parse, Flag};
let path = "[root]/etc/cron.d/sysupdate";
let kind = detect(path).unwrap();
let parsed = parse(kind, b"@reboot root /dev/shm/.x/run\n", path);
let job = &parsed.entries[0];
assert_eq!(job.summary(), "@reboot as root: /dev/shm/.x/run");
assert_eq!(flags(job), [Flag::TemporaryDirectory, Flag::AtReboot]);Structs§
- Account
- An account of
etc/passwd. - Authorized
Key - A key that may log in.
- Entry
- One job, setting, key, command line, library or rule.
- KeyOption
- An option before a key:
no-pty, orfrom="198.51.100.0/24". - PamRule
- A PAM rule:
type control module arguments. - Parsed
- A file’s entries.
- Password
- The state of an account’s password, from
etc/shadow. - Sudo
Rule - A sudoers rule:
users hosts = (run-as) TAGS: commands. - Udev
Pair - One
KEY{attribute}op"value"pair of a udev rule.
Enums§
- Detail
- What else a line holds, by what it is.
- Flag
- A suspicious trait.
- Kind
- A kind of file, each read its own way.
- Password
State - What a shadow password field holds.
Constants§
- VERSION
- This crate’s version, for records of what parsed them.
Functions§
- detect
- A file’s kind from its path on the host: relative to the root
(
etc/crontab), absolute (/etc/crontab), or as a collection stores it ([root]/etc/crontab,uac/[root]/etc/crontab);/or\separated.Nonefor files this crate doesn’t read. - flags
- What looks suspicious about
entry, inFlagorder. - parse
- Read a file of
kindfound atpathon the host. The path names the account for users’ crontabs, keys, start-up files and units.