Skip to main content Skills Marktplatz Entdecken und erkunden Sie KI-Skills, die von der Community erstellt wurden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Prompt kopierenPrompt-Details anzeigen Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu1804-v220-1-8-8Der Befehl bleibt in einer Zeile. Scrollen Sie horizontal, um ihn vor dem Kopieren vollständig zu prüfen.
Sie bevorzugen eine lokale Kopie? Laden Sie die Dateien herunter, die SkillsMP derzeit vorliegen.
ZIP herunterladen Herunterladen... Mehr aus diesem Repository Verwandte Berufe SOC
Basierend auf der SOC-Berufsklassifikation
name cis-ubuntu1804-v220-1-8-8 description Ensure GDM autorun-never is enabled category cis-networking version 2.2.0 author cyberstrike-official tags ["cis","ubuntu","linux","ubuntu-18.04","gdm","gnome","autorun-never","dconf"] cis_id 1.8.8 cis_benchmark CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 tech_stack ["ubuntu","linux"] cwe_ids [] chains_with [] prerequisites [] severity_boost {}
1.8.8 Ensure GDM autorun-never is enabled (Automated)
Profile Applicability
Level 1 - Server
Level 1 - Workstation
Description
The autorun-never setting allows the GNOME Desktop Display Manager to disable autorun through GDM.
Rationale
Malware on removable media may taking advantage of Autorun features when the media is inserted into a system and execute.
Audit Procedure
Command Line
Run the following script to verify that autorun-never is set to true for GDM:
#!/usr/bin/env bash
{
l_pkgoutput="" l_output="" l_output2=""
if command -v dpkg-query > /dev/null 2>&1; then
l_pq="dpkg-query -s"
elif command -v rpm > /dev/null 2>&1; then
l_pq="rpm -q"
fi
l_pcl="gdm gdm3"
for l_pn in $l_pcl ; do
$l_pq "$l_pn " > /dev/null 2>&1 && l_pkgoutput="$l_pkgoutput \n - Package: \"$l_pn \" exists on the system\n - checking configuration"
done
echo -e "$l_pkgoutput "
if [ -n ];
-e
l_kfile=
[ -f ];
l_gpname= .
[ -n ];
l_gpdir=
grep -Pq -- /etc/dconf/profile/*;
l_output=
l_output2=
[ -f ];
l_output=
l_output2=
[ -d ];
l_output=
l_output2=
grep -Pqrs -- ;
l_output=
l_output2=
l_output2=
l_output=
[ -z ];
-e
-e
[ -n ] && -e
}
"$l_pkgoutput "
then
echo
"$l_pkgoutput "
"$(grep -Prils -- '^\h*autorun-never\b' /etc/dconf/db/*.d) "
if
"$l_kfile "
then
"$(awk -F\/ '{split($(NF-1) ,a,"
");print a[1]}' <<< "
$l_kfile
")"
fi
if
"$l_gpname "
then
"/etc/dconf/db/$l_gpname .d"
if
"^\h*system-db:$l_gpname \b"
then
"$l_output \n - dconf database profile file \"$(grep -Pl -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*) \" exists"
else
"$l_output2 \n - dconf database profile isn't set"
fi
if
"/etc/dconf/db/$l_gpname "
then
"$l_output \n - The dconf database \"$l_gpname \" exists"
else
"$l_output2 \n - The dconf database \"$l_gpname \" doesn't exist"
fi
if
"$l_gpdir "
then
"$l_output \n - The dconf directory \"$l_gpdir \" exitst"
else
"$l_output2 \n - The dconf directory \"$l_gpdir \" doesn't exist"
fi
if
'^\h*autorun-never\h*=\h*true\b'
"$l_kfile "
then
"$l_output \n - \"autorun-never\" is set to true in: \"$l_kfile \""
else
"$l_output2 \n - \"autorun-never\" is not set correctly"
fi
else
"$l_output2 \n - \"autorun-never\" is not set"
fi
else
"$l_output \n - GNOME Desktop Manager package is not installed on the system\n - Recommendation is not applicable"
fi
if
"$l_output2 "
then
echo
"\n- Audit Result:\n ** PASS **\n$l_output \n"
else
echo
"\n- Audit Result:\n ** FAIL **\n - Reason(s) for audit failure:\n$l_output2 \n"
"$l_output "
echo
"\n- Correctly set:\n$l_output \n"
fi
Remediation
Command Line Run the following script to set autorun-never to true for GDM users:
#!/usr/bin/env bash
{
l_pkgoutput="" l_output="" l_output2=""
l_gpname="local"
if command -v dpkg-query > /dev/null 2>&1; then
l_pq="dpkg-query -s"
elif command -v rpm > /dev/null 2>&1; then
l_pq="rpm -q"
fi
l_pcl="gdm gdm3"
for l_pn in $l_pcl ; do
$l_pq "$l_pn " > /dev/null 2>&1 && l_pkgoutput="$l_pkgoutput \n - Package: \"$l_pn \" exists on the system\n - checking configuration"
done
echo -e "$l_pkgoutput "
if [ -n "$l_pkgoutput " ]; then
echo -e "$l_pkgoutput "
l_kfile="$(grep -Prils -- '^\h*autorun-never\b' /etc/dconf/db/*.d) "
if [ -f "$l_kfile " ]; then
l_gpname="$(awk -F\/ '{split($(NF-1) ,a," .");print a[1]}' <<< " $l_kfile ")"
echo " - updating dconf profile name to \"$l_gpname \""
fi
[ ! -f "$l_kfile " ] && l_kfile="/etc/dconf/db/$l_gpname .d/00-media-autorun"
if grep -Pq -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*; then
echo -e "\n - dconf database profile exists in: \"$(grep -Pl -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*) \""
else
[ ! -f "/etc/dconf/profile/user" ] && l_gpfile="/etc/dconf/profile/user" || l_gpfile="/etc/dconf/profile/user2"
echo -e " - creating dconf database profile"
{
echo -e "\nuser-db:user"
echo "system-db:$l_gpname "
} >> "$l_gpfile "
fi
l_gpdir="/etc/dconf/db/$l_gpname .d"
if [ -d "$l_gpdir " ]; then
echo " - The dconf database directory \"$l_gpdir \" exists"
else
echo " - creating dconf database directory \"$l_gpdir \""
mkdir "$l_gpdir "
fi
if grep -Pqs -- '^\h*autorun-never\h*=\h*true\b' "$l_kfile " ; then
echo " - \"autorun-never\" is set to true in: \"$l_kfile \""
else
echo " - creating or updating \"autorun-never\" entry in \"$l_kfile \""
if grep -Psq -- '^\h*autorun-never' "$l_kfile " ; then
sed -ri 's/^\s*autorun-never\s*=\s*\S+/autorun-never=true' "$l_kfile "
else
! grep -Psq -- '^\h*\[org\/gnome\/desktop\/media-handling\]\b' "$l_kfile " && echo '[org/gnome/desktop/media-handling]' >> "$l_kfile "
sed -ri '/^\s*\[org\/gnome\/desktop\/media-handling\]/a \\nautorun-never=true' "$l_kfile "
fi
fi
else
echo -e "\n - GNOME Desktop Manager package is not installed on the system\n - Recommendation is not applicable"
fi
dconf update
}
Default Value
References
NIST SP 800-53 Rev. 5: CM-1, CM-2, CM-6, CM-7, IA-5
CIS Controls Controls Version Control IG 1 IG 2 IG 3 v8 10.3 Disable Autorun and Autoplay for Removable Media X X X v7 8.5 Configure Devices Not To Auto-run Content X X X
MITRE ATT&CK Mappings Techniques / Sub-techniques Tactics Mitigations T1091, T1091.000 TA0001, TA0008 M1028