用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu1604-v200-5-3-2命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu1604-v200-5-3-2 |
| description | Ensure permissions on SSH private host key files are configured |
| category | cis-networking |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-16.04","ssh","remote-access"] |
| cis_id | 5.3.2 |
| cis_benchmark | CIS Ubuntu Linux 16.04 LTS Benchmark v2.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
An SSH private key is one of two files used in SSH public key authentication. In this authentication method, The possession of the private key is proof of identity. Only a private key that corresponds to a public key will be able to authenticate successfully. The private keys need to be stored and handled carefully, and no copies of the private key should be distributed.
If an unauthorized user obtains the private SSH host key file, the host could be impersonated.
Run the following command and verify Uid is 0/root and Gid is 0/root and permissions are 0600 or more restrictive:
find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec stat {} \;
File: '/etc/ssh/ssh_host_rsa_key'
Size: 1675 Blocks: 8 IO Block: 4096 regular file
Access: (0600/-rw-------) Uid: ( 0/ root) Gid: ( 0/ root)
File: '/etc/ssh/ssh_host_ecdsa_key'
Size: 227 Blocks: 8 IO Block: 4096 regular file
Access: (0600/-rw-------) Uid: ( 0/ root) Gid: ( 0/ root)
File: '/etc/ssh/ssh_host_ed25519_key'
Size: 399 Blocks: 8 IO Block: 4096 regular file
Access: (0600/-rw-------) Uid: ( 0/ root) Gid: ( 0/ root)
File: '/etc/ssh/ssh_host_dsa_key'
Size: 672 Blocks: 8 IO Block: 4096 regular file
Access: (0600/-rw-------) Uid: ( 0/ root) Gid: ( 0/ root)
Run the following commands to set permissions, ownership, and group on the private SSH host key files:
find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec chown root:root {} \;
find /etc/ssh -xdev -type f -name 'ssh_host_*_key' -exec chmod u-x,go-rwx {} \;
Access: (0600/-rw-------) Uid: ( 0/ root) Gid: ( 0/ root)
Version 7
14.6 Protect Information through Access Control Lists - Protect all information stored on systems with file system, network share, claims, application, or database specific access control lists. These controls will enforce the principle that only authorized individuals should have access to the information based on their need to access the information as a part of their responsibilities.
Automated