Cron Jobs
Read the cron jobs then read permissions on any scripts running
cat /etc/crontabSystemd timers could aslo be running which essentially do the same thing
Cron Paths
If the path of the script isn't a the full file path it will check the first path in the PATH variable for it first

Cron Wildcards
If we only have read permissions on a script but it is using a wildcard with another command, we can make that command run something malicious instead

With tar specifically we can make it run a script using touch and checkpoints
Cron File Overwrites
Check the file permissions on the scheduled script and add a reverse shell to it
Last updated
Was this helpful?