用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-apache24-9-6命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-apache24-9.6 |
| description | Ensure Timeout Limits for the Request Body is Set to 20 or Less (Manual) |
| category | cis-apache |
| version | 2.3.0 |
| author | cyberstrike-official |
| tags | ["cis","apache","linux","dos","timeout","slow-post","request-body"] |
| cis_id | 9.6 |
| cis_benchmark | CIS Apache HTTP Server 2.4 Benchmark v2.3.0 |
| tech_stack | ["linux","apache"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The RequestReadTimeout directive also allows setting timeout values for the body portion of a request. The directive provides for an initial timeout value, and a maximum timeout and minimum rate. The minimum rate specifies that after the initial timeout, the server will wait an additional 1 second for each N bytes received. The recommended setting is to have a maximum timeout of 20 seconds or less. The default value is body=20,MinRate=500.
It is not sufficient to timeout only on the header portion of the request, as the server will still be vulnerable to attacks like the OWASP Slow POST attack, which provide the body of the request very slowly. Therefore, the body portion of the request must have a timeout as well. A timeout of 20 seconds or less is recommended.
Perform the following to determine if the recommended state is implemented:
RequestReadTimeout directives and verify the configuration has a maximum body request timeout of 20 seconds or less.RequestReadTimeout directives, and the mod_reqtimeout module is being loaded, then the default value of 20 seconds is compliant with the benchmark recommendation.
RequestReadTimeout header=XXXXXX body=20,MinRate=XXXXXXXXXXLoad the mod_requesttimeout module in the Apache configuration with the following configuration.
LoadModule reqtimeout_module modules/mod_reqtimeout.so
Add a RequestReadTimeout directive similar to the one below with the maximum request body timeout value of 20 seconds or less.
RequestReadTimeout header=20-40,MinRate=500 body=20,MinRate=500
body=20,MinRate=500
v7: