Stealthy plist Persistence
Bypassing Security Mechanisms¶
macOS enforces strict permissions and integrity checks. Attackers may:
- Exploit sandboxed environments by creating plists in trusted directories like /Library/LaunchAgents (which are not typically monitored for unauthorized changes).
- Leverage Gatekeeper bypasses by signing plists with a trusted certificate (requires code signing capabilities).
Example:
# Create a signed plist in a trusted directory
sudo plutil -insert Label "com.apple.system.plist" /Library/LaunchAgents/com.apple.system.plist
sudo plutil -insert Program "/usr/bin/launchd" /Library/LaunchAgents/com.apple.system.plist
sudo chown root:wheel /Library/LaunchAgents/com.apple.system.plist
sudo chmod 644 /Library/LaunchAgents/com.apple.system.plist
Note: The /var/db/launchd.db/ directory is not a standard location for plist files. macOS stores launchd service configurations in /Library/LaunchDaemons and /Library/LaunchAgents.