Public bug reported:

1) Ubuntu 26.04
2) 5.0.2-0ubuntu1~26.04.1
3) Record every creation, replacement, or deletion of a user or system crontab 
entry in a system-controlled audit log that ordinary users can read (if 
desired) but cannot modify or delete. Only root (or a privileged process) 
should be able to alter the log.

Cron is a common persistence mechanism. A process running as a normal user can 
install or change a crontab, yet most systems provide little or no durable, 
user-immutable record of who created or modified the schedule. Existing cron 
execution logs only show when jobs ran, not when the schedule itself was 
changed. A user-controlled log file can be deleted or altered by the same 
malware that planted the crontab.
Proposed solution
1.  When the privileged crontab utility (or equivalent) installs, replaces, or 
removes a crontab, emit a structured audit record containing:
        •  Timestamp
        •  Real and effective user
        •  Action (create / replace / delete)
        •  Target user
        •  Optional hash or summary of the new content
2.  Store the record in a system-owned location (auditd, journald, or a 
dedicated root-only log) that is:
        •  Readable by the owning user (or by authorized auditors)
        •  Writable/deletable only by root
3.  Optionally extend the same protection to related locations (/etc/cron.d/, 
/etc/crontab, etc.).
Benefits
•  Clear forensic trail of schedule changes
•  Prevents malware running as the user from erasing evidence
•  Complements existing cron.allow/cron.deny and auditd watches
•  Minimal performance impact (only on crontab modification, not on job 
execution)
Implementation notes
Prefer leveraging the existing audit framework (auditd) or adding a lightweight 
log call inside the setuid crontab binary. Avoid placing the log under any 
user-writable directory.


4) User can modify or delete their event log.

** Affects: apparmor (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2170302

Title:
  Feature Request: Tamper-resistant logging of crontab creation and
  modification

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2170302/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to