T06 · System Persistence
- Location
SKILL.md:369- Finding
Persistent Always-On Web Service Enabled Across Login Sessions
- Content
View full analysis
~/.config/systemd/user/hzl-web.service systemctl --user daemon-reload systemctl --user enable --now hzl-web loginctl enable-linger $USER ``` ### Technical Analysis The documented procedure creates a systemd user unit, reloads the user service manager, enables and immediately starts the HZL web service, and then enables lingering for the current user. Enabling lingering allows the user's systemd service manager to remain active when the user is not logged in. Consequently, the HZL web server can continue running after the initiating agent session or interactive login has ended and may start again on subsequent boots. Although the section describes this as an always-on dashboard configuration, these commands establish cross-session persistence. The instructions do not require an explicit confirmation immediately before enabling persistence, do not restrict the generated service to the loopback interface, and do not document authentication requirements or a removal procedure. ### Attack Path 1. An agent loads the skill and follows the “Web dashboard (always-on, Linux)” procedure. 2. `hzl serve --print-systemd` generates a user service definition. 3. The generated definition is written to `~/.config/systemd/user/hzl-web.service`. 4. `systemctl --user enable --now hzl-web` enables the service for future starts and starts it immediately. 5. `loginctl enable-linger $USER` permits the user service manager and the HZL service to remain active without an interactive login. 6. The service persists beyond the skill run and may expose the task ledger or connected gateway functionality for as long as it remains enabled. ### Impact Assessment The resulting service runs with the privileges of the affected user rather tha ...[truncated 488 chars]- Remediation
View remediation
