Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-apache24-2-8명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | cis-apache24-2.8 |
| description | Ensure the Info Module Is Disabled |
| category | cis-apache |
| version | 2.3.0 |
| author | cyberstrike-official |
| tags | ["cis","apache","linux","modules","info"] |
| cis_id | 2.8 |
| cis_benchmark | CIS Apache HTTP Server 2.4 Benchmark v2.3.0 |
| tech_stack | ["linux","apache"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The Apache mod_info module provides information on the server configuration via access to a /server-info URL location.
While having server configuration information available as a web page may be convenient it's recommended that this module NOT be enabled. Once mod_info is loaded into the server, its handler capability is available in all per-directory .htaccess files and can leak sensitive information from the configuration directives of other Apache modules such as system paths, usernames/passwords, database names, etc.
Perform the following to determine if the Info module is enabled.
Run the httpd server with the -M option to list enabled modules:
# httpd -M | egrep 'info_module'
Note: If the module is correctly disabled, there will be no output when executing the above command.
Perform either one of the following to disable the mod_info module:
./configure script without including the mod_info in the --enable-modules= configure script options.
$ cd $DOWNLOAD_HTTPD$ ./configuremod_info module from the httpd.conf file.
##LoadModule info_module modules/mod_info.soThe mod_info module is not enabled with a default source build.