cron-job-abuse
Find World-Writable Files (Potential Cron Job Scripts)
find / -path /proc -prune -o -type f -perm -o+w -exec ls -lah {} + 2>/dev/nullList Files in a Suspicious Directory
ls -lah /dmz-backups/Check Cron Jobs (If You Have Permissions)
crontab -l # Current user's cron jobs
sudo crontab -l # Root user's cron jobs (if accessible)
cat /etc/crontab # System-wide cron jobs Check /etc/cron.d/ for Scheduled Jobs
/etc/cron.d/ for Scheduled JobsUse pspy to Monitor Background Processes
pspy to Monitor Background ProcessesModify a Vulnerable Script (Example: /dmz-backups/backup.sh)
/dmz-backups/backup.sh)Modify a Writable Cron Job File (Example: /etc/cron.d/vulnerable_cron)
/etc/cron.d/vulnerable_cron)Key Improvements and Explanations:
Last updated