Skip to main content Skills Marketplace Descubra e explore skills de IA criadas pela comunidade.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Copiar promptMostrar detalhes do prompt Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu1804-v220-1-8-8O comando permanece em uma só linha. Role horizontalmente para revisá-lo antes de copiar.
Prefere uma cópia local? Baixe os arquivos disponíveis atualmente no SkillsMP.
Baixar Zip Baixando... Ocupações relacionadas SOC
Baseado na classificação ocupacional SOC
name cis-ubuntu1804-v220-1-8-8 description Ensure GDM autorun-never is enabled category cis-networking version 2.2.0 author cyberstrike-official tags ["cis","ubuntu","linux","ubuntu-18.04","gdm","gnome","autorun-never","dconf"] cis_id 1.8.8 cis_benchmark CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 tech_stack ["ubuntu","linux"] cwe_ids [] chains_with [] prerequisites [] severity_boost {}
1.8.8 Ensure GDM autorun-never is enabled (Automated)
Profile Applicability
Level 1 - Server
Level 1 - Workstation
Description
The autorun-never setting allows the GNOME Desktop Display Manager to disable autorun through GDM.
Rationale
Malware on removable media may taking advantage of Autorun features when the media is inserted into a system and execute.
Audit Procedure
Command Line
Run the following script to verify that autorun-never is set to true for GDM:
#!/usr/bin/env bash
{
l_pkgoutput="" l_output="" l_output2=""
if command -v dpkg-query > /dev/null 2>&1; then
l_pq="dpkg-query -s"
elif command -v rpm > /dev/null 2>&1; then
l_pq="rpm -q"
fi
l_pcl="gdm gdm3"
for l_pn in $l_pcl ; do
$l_pq "$l_pn " > /dev/null 2>&1 && l_pkgoutput="$l_pkgoutput \n - Package: \"$l_pn \" exists on the system\n - checking configuration"
done
echo -e "$l_pkgoutput "
if [ -n ];
-e
l_kfile=
[ -f ];
l_gpname= .
[ -n ];
l_gpdir=
grep -Pq -- /etc/dconf/profile/*;
l_output=
l_output2=
[ -f ];
l_output=
l_output2=
[ -d ];
l_output=
l_output2=
grep -Pqrs -- ;
l_output=
l_output2=
l_output2=
l_output=
[ -z ];
-e
-e
[ -n ] && -e
}
"$l_pkgoutput "
then
echo
"$l_pkgoutput "
"$(grep -Prils -- '^\h*autorun-never\b' /etc/dconf/db/*.d) "
if
"$l_kfile "
then
"$(awk -F\/ '{split($(NF-1) ,a,"
");print a[1]}' <<< "
$l_kfile
")"
fi
if
"$l_gpname "
then
"/etc/dconf/db/$l_gpname .d"
if
"^\h*system-db:$l_gpname \b"
then
"$l_output \n - dconf database profile file \"$(grep -Pl -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*) \" exists"
else
"$l_output2 \n - dconf database profile isn't set"
fi
if
"/etc/dconf/db/$l_gpname "
then
"$l_output \n - The dconf database \"$l_gpname \" exists"
else
"$l_output2 \n - The dconf database \"$l_gpname \" doesn't exist"
fi
if
"$l_gpdir "
then
"$l_output \n - The dconf directory \"$l_gpdir \" exitst"
else
"$l_output2 \n - The dconf directory \"$l_gpdir \" doesn't exist"
fi
if
'^\h*autorun-never\h*=\h*true\b'
"$l_kfile "
then
"$l_output \n - \"autorun-never\" is set to true in: \"$l_kfile \""
else
"$l_output2 \n - \"autorun-never\" is not set correctly"
fi
else
"$l_output2 \n - \"autorun-never\" is not set"
fi
else
"$l_output \n - GNOME Desktop Manager package is not installed on the system\n - Recommendation is not applicable"
fi
if
"$l_output2 "
then
echo
"\n- Audit Result:\n ** PASS **\n$l_output \n"
else
echo
"\n- Audit Result:\n ** FAIL **\n - Reason(s) for audit failure:\n$l_output2 \n"
"$l_output "
echo
"\n- Correctly set:\n$l_output \n"
fi
Remediation
Command Line Run the following script to set autorun-never to true for GDM users:
#!/usr/bin/env bash
{
l_pkgoutput="" l_output="" l_output2=""
l_gpname="local"
if command -v dpkg-query > /dev/null 2>&1; then
l_pq="dpkg-query -s"
elif command -v rpm > /dev/null 2>&1; then
l_pq="rpm -q"
fi
l_pcl="gdm gdm3"
for l_pn in $l_pcl ; do
$l_pq "$l_pn " > /dev/null 2>&1 && l_pkgoutput="$l_pkgoutput \n - Package: \"$l_pn \" exists on the system\n - checking configuration"
done
echo -e "$l_pkgoutput "
if [ -n "$l_pkgoutput " ]; then
echo -e "$l_pkgoutput "
l_kfile="$(grep -Prils -- '^\h*autorun-never\b' /etc/dconf/db/*.d) "
if [ -f "$l_kfile " ]; then
l_gpname="$(awk -F\/ '{split($(NF-1) ,a," .");print a[1]}' <<< " $l_kfile ")"
echo " - updating dconf profile name to \"$l_gpname \""
fi
[ ! -f "$l_kfile " ] && l_kfile="/etc/dconf/db/$l_gpname .d/00-media-autorun"
if grep -Pq -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*; then
echo -e "\n - dconf database profile exists in: \"$(grep -Pl -- "^\h*system-db:$l_gpname \b" /etc/dconf/profile/*) \""
else
[ ! -f "/etc/dconf/profile/user" ] && l_gpfile="/etc/dconf/profile/user" || l_gpfile="/etc/dconf/profile/user2"
echo -e " - creating dconf database profile"
{
echo -e "\nuser-db:user"
echo "system-db:$l_gpname "
} >> "$l_gpfile "
fi
l_gpdir="/etc/dconf/db/$l_gpname .d"
if [ -d "$l_gpdir " ]; then
echo " - The dconf database directory \"$l_gpdir \" exists"
else
echo " - creating dconf database directory \"$l_gpdir \""
mkdir "$l_gpdir "
fi
if grep -Pqs -- '^\h*autorun-never\h*=\h*true\b' "$l_kfile " ; then
echo " - \"autorun-never\" is set to true in: \"$l_kfile \""
else
echo " - creating or updating \"autorun-never\" entry in \"$l_kfile \""
if grep -Psq -- '^\h*autorun-never' "$l_kfile " ; then
sed -ri 's/^\s*autorun-never\s*=\s*\S+/autorun-never=true' "$l_kfile "
else
! grep -Psq -- '^\h*\[org\/gnome\/desktop\/media-handling\]\b' "$l_kfile " && echo '[org/gnome/desktop/media-handling]' >> "$l_kfile "
sed -ri '/^\s*\[org\/gnome\/desktop\/media-handling\]/a \\nautorun-never=true' "$l_kfile "
fi
fi
else
echo -e "\n - GNOME Desktop Manager package is not installed on the system\n - Recommendation is not applicable"
fi
dconf update
}
Default Value
References
NIST SP 800-53 Rev. 5: CM-1, CM-2, CM-6, CM-7, IA-5
CIS Controls Controls Version Control IG 1 IG 2 IG 3 v8 10.3 Disable Autorun and Autoplay for Removable Media X X X v7 8.5 Configure Devices Not To Auto-run Content X X X
MITRE ATT&CK Mappings Techniques / Sub-techniques Tactics Mitigations T1091, T1091.000 TA0001, TA0008 M1028