用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu2004-v300-5-4-1-4命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu2004-v300-5-4-1-4 |
| description | Ensure strong password hashing algorithm is configured |
| category | cis-iam |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","users","authentication"] |
| cis_id | 5.4.1.4 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
A cryptographic hash function converts an arbitrary-length input into a fixed length output. Password hashing performs a one-way transformation of a password, turning the password into another string, called the hashed password.
ENCRYPT_METHOD (string) - This defines the system default encryption algorithm for encrypting passwords (if no algorithm are specified on the command line). It can take one of these values:
MD5 - MD5-based algorithm will be used for encrypting passwordSHA256 - SHA256-based algorithm will be used for encrypting passwordSHA512 - SHA512-based algorithm will be used for encrypting passwordBCRYPT - BCRYPT-based algorithm will be used for encrypting passwordYESCRYPT - YESCRYPT-based algorithm will be used for encrypting passwordDES - DES-based algorithm will be used for encrypting password (default)Note:
MD5_CRYPT_ENAB variable.The SHA-512 and yescrypt algorithms provide a stronger hash than other algorithms used by Linux for password hash generation. A stronger hash provides additional protection to the system by increasing the level of effort needed for an attacker to successfully determine local group passwords.
Run the following command to verify the hashing algorithm is sha512 or yescrypt in /etc/login.defs:
# grep -Pi -- '^\h*ENCRYPT_METHOD\h+(SHA512|yescrypt)\b' /etc/login.defs
Example output:
ENCRYPT_METHOD SHA512
- OR -
ENCRYPT_METHOD YESCRYPT
Output should show ENCRYPT_METHOD set to SHA512 or YESCRYPT.
Edit /etc/login.defs and set the ENCRYPT_METHOD to SHA512 or YESCRYPT:
ENCRYPT_METHOD <HASHING_ALGORITHM>
Example:
ENCRYPT_METHOD YESCRYPT
Note:
sha512 or yescrypt.sha512 or yescrypt, once it is changed, it is recommended that all group passwords be updated to use the stronger hashing algorithm./etc/login.defs and the PAM configurationENCRYPT_METHOD SHA512
v8 - 3.11 Encrypt Sensitive Data at Rest: Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data. (IG 2, IG 3)
v7 - 16.4 Encrypt or Hash all Authentication Credentials: Encrypt or hash with a salt all authentication credentials when stored. (IG 2, IG 3)
MITRE ATT&CK Mappings: T1003, T1003.008, T1110, T1110.002 - Tactics: TA0006 - Mitigations: M1041