用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu1604-v200-1-8-3命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu1604-v200-1-8-3 |
| description | Ensure disable-user-list is enabled |
| category | cis-iam |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-16.04","gdm","gnome","user-list","login","display-manager"] |
| cis_id | 1.8.3 |
| cis_benchmark | CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 |
| tech_stack |
| ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
GDM is the GNOME Display Manager which handles graphical login for GNOME based systems.
The disable-user-list option controls is a list of users is displayed on the login screen.
Displaying the user list eliminates half of the Userid/Password equation that an unauthorized person would need to log on.
Run the following command to verify that disable-user-list is enabled:
grep -E '^\s*disable-user-list\s*=\s*true\b' /etc/gdm3/greeter.dconf-defaults
Expected output: disable-user-list=true
The disable-user-list option should be set to true in the GDM configuration.
Edit or create the file /etc/gdm3/greeter.dconf-defaults and edit or add the following:
[org/gnome/login-screen]
banner-message-enable=true
banner-message-text='<banner message>'
disable-user-list=true
Run the following command to re-load GDM on the next login or reboot:
dpkg-reconfigure gdm3
If a different GUI login service is in use and required on the system, consult your documentation to disable displaying the user list.
false
None.
| Controls Version | Control |
|---|---|
| v7 | 5.1 Establish Secure Configurations |
Automated