用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu2004-v300-2-1-13命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu2004-v300-2-1-13 |
| description | Ensure rsync services are not in use |
| category | cis-networking |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","services"] |
| cis_id | 2.1.13 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The rsync service can be used to synchronize files between systems over network links.
The rsync service presents a security risk as it uses unencrypted protocols for communication. Unless there is a need to run rsync as a daemon, it is recommended that the rsync service be disabled to reduce the remote attack surface.
Run the following command to verify rsync is not installed:
# dpkg-query -W -f='${binary:Package}\t${Status}\t${db:Status-Status}\n' rsync
If installed, run:
# systemctl is-enabled rsync.service
# systemctl is-active rsync.service
Verify the service is not enabled and not active.
rsync should not be installed as a service, or if installed, the service should be stopped and masked.
Run the following commands to stop, mask, and purge rsync:
# systemctl stop rsync.service
# systemctl mask rsync.service
# apt purge rsync
rsync may be installed but the daemon is not enabled by default.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | x | x | |
| v7 | 9.2 Ensure Only Approved Ports, Protocols and Services Are Running | x | x |
MITRE ATT&CK Mappings: T1105, T1203, T1210, T1543, T1543.002, T1570 | TA0008 | M1042