Hijacks
Batch Script Hijack
# List the file's contents
> type c:\tasks\my_job
<SNIP>
<Interval>PT1M</Interval> # Runs every minute
<Exec>
<Command>C:\Windows\System32\cmd.exe</Command>
<Arguments>/c C:\Windows\Logs\my_task.bat</Arguments> # Executes this file
</Exec>
<Principals>
<UserId>Administrator</UserId> # Runs as Administrator
<SNIP>
# Check the batch file's permissions
> icacls c:\windows\logs\my_task.bat
c:\windows\logs\my_task.bat Everyone:(RX,W) # File is writableLast updated