用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-apache24-2-8命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-apache24-2.8 |
| description | Ensure the Info Module Is Disabled |
| category | cis-apache |
| version | 2.3.0 |
| author | cyberstrike-official |
| tags | ["cis","apache","linux","modules","info"] |
| cis_id | 2.8 |
| cis_benchmark | CIS Apache HTTP Server 2.4 Benchmark v2.3.0 |
| tech_stack | ["linux","apache"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The Apache mod_info module provides information on the server configuration via access to a /server-info URL location.
While having server configuration information available as a web page may be convenient it's recommended that this module NOT be enabled. Once mod_info is loaded into the server, its handler capability is available in all per-directory .htaccess files and can leak sensitive information from the configuration directives of other Apache modules such as system paths, usernames/passwords, database names, etc.
Perform the following to determine if the Info module is enabled.
Run the httpd server with the -M option to list enabled modules:
# httpd -M | egrep 'info_module'
Note: If the module is correctly disabled, there will be no output when executing the above command.
Perform either one of the following to disable the mod_info module:
./configure script without including the mod_info in the --enable-modules= configure script options.
$ cd $DOWNLOAD_HTTPD$ ./configuremod_info module from the httpd.conf file.
##LoadModule info_module modules/mod_info.soThe mod_info module is not enabled with a default source build.