用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-bind9-v301-3-3命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-bind9-v301-3-3 |
| description | Restrict Query Origins (Manual) |
| category | cis-bind |
| version | 3.0.1 |
| author | cyberstrike-official |
| tags | ["cis","bind","dns","isc-bind","bind9","restricting-queries"] |
| cis_id | 3.3 |
| cis_benchmark | CIS ISC BIND DNS Server 9.9 Benchmark v3.0.1 |
| tech_stack | ["bind","isc-bind","dns","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
BIND can be configured to restrict access to its query services based on source IP address. It is recommended that the allow-query option be used to restrict access to only the networks authorized to use the name server. For an external authoritative only name server, the authorized networks may include all networks, however for internal authoritative or caching name servers the authorized networks should be explicitly configured.
Using allow-query in conjunction with an ACL of trusted networks will reduce the risk of unauthorized access to name services content. Additionally, the exposure of vulnerabilities present in BIND's query handlers is reduced by this configuration as requests with an untrusted source will be rejected before the request is fully parsed by named. Keep in mind however, that the source IP addresses can be easily spoofed, and the firewall and network architecture also needs to protect internal name servers from external spoofed requests.
Not Applicable
Verify that the BIND configuration files contain a global allow-query option with only the predefined ACL localhost and an ACL of the explicitly authorized networks. For an external authoritative only name server, the authorized networks may be the ACL any which represents any IPv4 or IPV6 host, but for caching and internal name servers, the authorized_networks should be an ACL with an explicit list of networks. The name of the ACL does not have to be authorized_networks.
$ grep allow-query $CONFIG_FILES
allow-query { localhost; authorized_networks };
For an external authoritative only name server:
$ grep allow-query $CONFIG_FILES
allow-query { any };
For remediation:
named.conf file.acl authorized_networks { 10.10.32.0/24; 10.10.34.0/24; . . . };
named.conf file with the localhost ACL and the authorized trusted networks ACL.allow-query { localhost; authorized_networks };
The default package install allows queries only from localhost.
Not Applicable
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v6 | 9 - Limitation and Control of Network Ports, Protocols, and Services | N | Y | Y |
| Tactic | Technique |
|---|---|
| Reconnaissance | T1590 - Gather Victim Network Information |
| Discovery | T1046 - Network Service Scanning |