T06 · System Persistence
- Location
SKILL.md:80- Finding
SSH Service Is Persistently Enabled Without Explicit Confirmation or Hardening
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 80
Vulnerability Type: Persistent startup service and unnecessary long-term network exposure
Risk Level: MediumComplete Code Snippet:
bash # SSH enablement sudo systemctl enable ssh && sudo systemctl start sshTechnical Analysis
The command performs two distinct operations with elevated privileges:
systemctl start sshstarts the SSH service for the current system session.systemctl enable sshmodifies startup configuration so that SSH is automatically launched on subsequent boots.
Starting SSH is consistent with the Skill's declared remote-access functionality. However, automatically enabling it across reboots creates persistent network exposure beyond what is required for a temporary remote-access request. The instruction does not require explicit user confirmation for persistence and does not first assess authentication policy, root login, password authentication, listening interfaces, or firewall restrictions.
This does not establish that the Skill intentionally installs a backdoor. Nevertheless, it creates a persistent service that may be reachable by untrusted networks and therefore exceeds minimum privilege and exposure requirements when only temporary SSH access is needed.
Attack Path
- A user follows the documented command to obtain SSH access.
- The command enables SSH at boot as root and immediately starts the service.
- SSH remains available after reboots, even if the user intended only temporary access.
- A network-adjacent or Internet-based attacker discovers the exposed SSH port.
- The attacker attempts credential guessing or exploits any independently vulnerable SSH configuration.
- If authentication is compromised, the attacker obtains the permissions of the affected SSH account and may subsequently attempt local privilege escalation.
Impact Assessment
The immediate impact is ...[truncated 606 chars]
- Remediation
View remediation
Remediation Suggestions
- Use
sudo systemctl start sshfor temporary access by default. - Require explicit user confirmation before running
sudo systemctl enable ssh. - Clearly explain that
enablepersists across reboots. - Provide a rollback command:
bash sudo systemctl disable --now ssh - Require key-based authentication and disable password authentication where practical.
- Disable direct root login by setting
PermitRootLogin no. - Restrict SSH to trusted interfaces, source addresses, or management networks through firewall rules.
- Verify configuration with
sshd -Tand service exposure withss -lntp. - Instruct users to stop or disable SSH after remote maintenance is complete.
- Use
