Skip to main content Skills Marketplace Découvrez et explorez les compétences IA créées par la communauté.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Copier le promptAfficher les détails du prompt Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu1804-v220-1-8-8La commande reste sur une seule ligne. Faites défiler horizontalement pour la vérifier avant de la copier.
Vous préférez une copie locale ? Téléchargez les fichiers actuellement disponibles dans SkillsMP.
Télécharger Zip Téléchargement... Métiers associés SOC
Basé sur la classification professionnelle SOC
name cis-ubuntu1804-v220-1-8-8 description Ensure GDM autorun-never is enabled category cis-networking version 2.2.0 author cyberstrike-official tags ["cis","ubuntu","linux","ubuntu-18.04","gdm","gnome","autorun-never","dconf"] cis_id 1.8.8 cis_benchmark CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 tech_stack ["ubuntu","linux"] cwe_ids [] chains_with [] prerequisites [] severity_boost {}
1.8.8 Ensure GDM autorun-never is enabled (Automated)
Profile Applicability
Level 1 - Server
Level 1 - Workstation
Description
The autorun-never setting allows the GNOME Desktop Display Manager to disable autorun through GDM.
Rationale
Malware on removable media may taking advantage of Autorun features when the media is inserted into a system and execute.
Audit Procedure
Command Line
Run the following script to verify that autorun-never is set to true for GDM:
#!/usr/bin/env bash
{
l_pkgoutput="" l_output="" l_output2=""
if command -v dpkg-query > /dev/null 2>&1; then
l_pq="dpkg-query -s"
elif command -v rpm > /dev/null 2>&1; then
l_pq="rpm -q"
fi
l_pcl="gdm gdm3"
for l_pn in $l_pcl ; do
$l_pq "$l_pn " > /dev/null 2>&1 && l_pkgoutput="$l_pkgoutput \n - Package: \"$l_pn \" exists on the system\n - checking configuration"
done
echo -e "$l_pkgoutput "
if [ -n ];
-e
l_kfile=
[ -f ];
l_gpname= .
[ -n ];
l_gpdir=
grep -Pq -- /etc/dconf/profile/*;
l_output=
l_output2=
[ -f ];
l_output=
l_output2=
[ -d ];
l_output=
l_output2=
grep -Pqrs -- ;
l_output=
l_output2=
l_output2=
l_output=
[ -z ];
-e
-e
[ -n ] && -e
}
"$l_pkgoutput "
then
echo
"$l_pkgoutput "
"$(grep -Prils -- '^\h*autorun-never\b' /etc/dconf/db/*.d) "
if
"$l_kfile "
then
"$(awk -F\/ '{split($(NF-1) ,a,"
");print a[1]}' <<< "
$l_kfile
")"
fi
if
"$l_gpname "
then
"/etc/dconf/db/$l_gpname .d"
if
"^\h*system-db:$l_gpname \b"
then
"$l_output \n - dconf database profile file \"$(grep -Pl -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*) \" exists"
else
"$l_output2 \n - dconf database profile isn't set"
fi
if
"/etc/dconf/db/$l_gpname "
then
"$l_output \n - The dconf database \"$l_gpname \" exists"
else
"$l_output2 \n - The dconf database \"$l_gpname \" doesn't exist"
fi
if
"$l_gpdir "
then
"$l_output \n - The dconf directory \"$l_gpdir \" exitst"
else
"$l_output2 \n - The dconf directory \"$l_gpdir \" doesn't exist"
fi
if
'^\h*autorun-never\h*=\h*true\b'
"$l_kfile "
then
"$l_output \n - \"autorun-never\" is set to true in: \"$l_kfile \""
else
"$l_output2 \n - \"autorun-never\" is not set correctly"
fi
else
"$l_output2 \n - \"autorun-never\" is not set"
fi
else
"$l_output \n - GNOME Desktop Manager package is not installed on the system\n - Recommendation is not applicable"
fi
if
"$l_output2 "
then
echo
"\n- Audit Result:\n ** PASS **\n$l_output \n"
else
echo
"\n- Audit Result:\n ** FAIL **\n - Reason(s) for audit failure:\n$l_output2 \n"
"$l_output "
echo
"\n- Correctly set:\n$l_output \n"
fi
Remediation
Command Line Run the following script to set autorun-never to true for GDM users:
#!/usr/bin/env bash
{
l_pkgoutput="" l_output="" l_output2=""
l_gpname="local"
if command -v dpkg-query > /dev/null 2>&1; then
l_pq="dpkg-query -s"
elif command -v rpm > /dev/null 2>&1; then
l_pq="rpm -q"
fi
l_pcl="gdm gdm3"
for l_pn in $l_pcl ; do
$l_pq "$l_pn " > /dev/null 2>&1 && l_pkgoutput="$l_pkgoutput \n - Package: \"$l_pn \" exists on the system\n - checking configuration"
done
echo -e "$l_pkgoutput "
if [ -n "$l_pkgoutput " ]; then
echo -e "$l_pkgoutput "
l_kfile="$(grep -Prils -- '^\h*autorun-never\b' /etc/dconf/db/*.d) "
if [ -f "$l_kfile " ]; then
l_gpname="$(awk -F\/ '{split($(NF-1) ,a," .");print a[1]}' <<< " $l_kfile ")"
echo " - updating dconf profile name to \"$l_gpname \""
fi
[ ! -f "$l_kfile " ] && l_kfile="/etc/dconf/db/$l_gpname .d/00-media-autorun"
if grep -Pq -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*; then
echo -e "\n - dconf database profile exists in: \"$(grep -Pl -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*) \""
else
[ ! -f "/etc/dconf/profile/user" ] && l_gpfile="/etc/dconf/profile/user" || l_gpfile="/etc/dconf/profile/user2"
echo -e " - creating dconf database profile"
{
echo -e "\nuser-db:user"
echo "system-db:$l_gpname "
} >> "$l_gpfile "
fi
l_gpdir="/etc/dconf/db/$l_gpname .d"
if [ -d "$l_gpdir " ]; then
echo " - The dconf database directory \"$l_gpdir \" exists"
else
echo " - creating dconf database directory \"$l_gpdir \""
mkdir "$l_gpdir "
fi
if grep -Pqs -- '^\h*autorun-never\h*=\h*true\b' "$l_kfile " ; then
echo " - \"autorun-never\" is set to true in: \"$l_kfile \""
else
echo " - creating or updating \"autorun-never\" entry in \"$l_kfile \""
if grep -Psq -- '^\h*autorun-never' "$l_kfile " ; then
sed -ri 's/^\s*autorun-never\s*=\s*\S+/autorun-never=true' "$l_kfile "
else
! grep -Psq -- '^\h*\[org\/gnome\/desktop\/media-handling\]\b' "$l_kfile " && echo '[org/gnome/desktop/media-handling]' >> "$l_kfile "
sed -ri '/^\s*\[org\/gnome\/desktop\/media-handling\]/a \\nautorun-never=true' "$l_kfile "
fi
fi
else
echo -e "\n - GNOME Desktop Manager package is not installed on the system\n - Recommendation is not applicable"
fi
dconf update
}
Default Value
References
NIST SP 800-53 Rev. 5: CM-1, CM-2, CM-6, CM-7, IA-5
CIS Controls Controls Version Control IG 1 IG 2 IG 3 v8 10.3 Disable Autorun and Autoplay for Removable Media X X X v7 8.5 Configure Devices Not To Auto-run Content X X X
MITRE ATT&CK Mappings Techniques / Sub-techniques Tactics Mitigations T1091, T1091.000 TA0001, TA0008 M1028