用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu1804-v220-3-4-3-3-4命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu1804-v220-3-4-3-3-4 |
| description | Ensure ip6tables firewall rules exist for all open ports |
| category | cis-networking |
| version | 2.2.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-18.04","networking","firewall","iptables","ipv6"] |
| cis_id | 3.4.3.3.4 |
| cis_benchmark | CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Any ports that have been opened on non-loopback addresses need firewall rules to govern traffic.
Without a firewall rule configured for open ports default firewall policy will drop all packets to these ports.
Run the following command to determine open ports:
ss -6tuln
Run the following command to determine firewall rules:
ip6tables -L INPUT -v -n
Verify all open ports listening on non-localhost addresses have at least one firewall rule.
-OR-
Verify IPv6 is disabled: Run the following script. Output will confirm if IPv6 is enabled on the system.
#!/usr/bin/bash
{
if grep -Pqs '^\h*0\b' /sys/module/ipv6/parameters/disable; then
echo -e " - IPv6 is enabled on the system"
else
echo -e " - IPv6 is not enabled on the system"
fi
}
Each open IPv6 port should have a corresponding ip6tables rule. Or IPv6 is not enabled on the system.
For each port identified in the audit which does not have a firewall rule establish a proper rule for accepting inbound connections:
ip6tables -A INPUT -p <protocol> --dport <port> -m state --state NEW -j ACCEPT
No firewall rules are configured by default.
Version 8
4.4 Implement and Manage a Firewall on Servers - Implement and manage a firewall on servers, where supported.
4.5 Implement and Manage a Firewall on End-User Devices - Implement and manage a host-based firewall or port-filtering tool on end-user devices.
Version 7
9.4 Apply Host-based Firewalls or Port Filtering - Apply host-based firewalls or port filtering tools on end systems, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
Automated