pub enum Flag {
Show 18 variants
TemporaryDirectory,
DownloadToShell,
Base64Decoding,
ReverseShell,
AtReboot,
ForcedCommand,
Preload,
SudoWithoutPassword,
PamExec,
PamAcceptsAnyPassword,
PamModuleElsewhere,
RootPasswordLogin,
EmptyPasswords,
KeysElsewhere,
ModprobeCommand,
UidZero,
NoPasswordNeeded,
SystemAccountShell,
}Expand description
A suspicious trait.
Variants§
TemporaryDirectory
The command runs something from, or works in, /tmp, /var/tmp
or /dev/shm: anyone can write there, and /dev/shm leaves nothing
on disk.
DownloadToShell
curl or wget output fed to a shell (curl … | sh,
bash -c "$(wget …)"): code fetched and run, never kept.
Base64Decoding
Base64 decoding (base64 -d, openssl base64 -d, b64decode):
a payload hidden from a casual read.
ReverseShell
nc, ncat, netcat, socat, or bash’s /dev/tcp/ and
/dev/udp/: the usual makings of a reverse shell.
AtReboot
A cron job run at every boot (@reboot).
ForcedCommand
A key that may only run a forced command (command="…"): sometimes
a restricted backup key, sometimes a backdoor run at every login.
Preload
A library in ld.so.preload, loaded into every program: distributions ship none, rootkits use it to hide.
SudoWithoutPassword
sudo without a password for every command (NOPASSWD: ALL), or
without authentication at all (Defaults !authenticate).
PamExec
A PAM rule running a program (pam_exec.so): at every login, with
the password if expose_authtok is set.
PamAcceptsAnyPassword
auth sufficient pam_permit.so: any password accepted.
PamModuleElsewhere
A PAM module given by a path outside the system’s module
directories (/lib/…/security, /usr/lib/…/security).
RootPasswordLogin
PermitRootLogin yes: root may log in over SSH with a password.
EmptyPasswords
PermitEmptyPasswords yes: accounts without a password may log in
over SSH.
KeysElsewhere
Keys sshd accepts read from somewhere else than the homes’
.ssh/authorized_keys (AuthorizedKeysFile), or from a program
(AuthorizedKeysCommand).
ModprobeCommand
modprobe runs a command instead of loading or unloading a module
(install, remove), other than /bin/true or /bin/false, the
usual way to block one.
UidZero
An account with id 0 other than root: root’s power under another name.
NoPasswordNeeded
An account without a password (an empty field in etc/passwd or
etc/shadow): it logs in with none where PAM allows it.
SystemAccountShell
A system account (id 1 to 999) whose shell lets it log in: a
service account turned into a way in (www-data given
/bin/bash). Some ship that way (postgres on Debian).