用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-bind9-v301-2-6命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-bind9-v301-2-6 |
| description | Set Group named or root for BIND Directories and Files (Automated) |
| category | cis-bind |
| version | 3.0.1 |
| author | cyberstrike-official |
| tags | ["cis","bind","dns","isc-bind","bind9","permissions-ownership"] |
| cis_id | 2.6 |
| cis_benchmark | CIS ISC BIND DNS Server 9.9 Benchmark v3.0.1 |
| tech_stack | ["bind","isc-bind","dns","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
All the BIND directories and files should have a group of either named or root.
In general, the BIND directories and files default to a group of named, however some system files may have a group of root. Examples of system files include chroot'ed system device files. Either group root or named is accepted, as the intent is to prevent unexpected group ids, from getting inappropriate access to BIND files. Run time directories to which BIND will need write access should have a group of named, so that write access may be granted via the group permissions.
Not Applicable
Ensure that the BIND benchmark variables used below are set as described in the benchmark overview. Run the command below to ensure that all BIND directories and files have a group of either named or root.
# find $BIND_HOME $RUNDIR \! \( -group root -o -group named \) -ls
There should be no files listed in the output from the find command.
Run the command below to change all BIND directories and files to the group named.
chgrp -R named $BIND_HOME $RUNDIR
The default rpm install has all directories and files in the BIND home and the run time directory with a group of named.
Not Applicable
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v6 | 14.4 - Protect Information with Access Control Lists | Y | Y | Y |
| Tactic | Technique |
|---|---|
| Defense Evasion | T1222 - File and Directory Permissions Modification |
| Persistence | T1546 - Event Triggered Execution |