用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-nginx-v300-2-2-3命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
正在显示 SKILL.md
基于 SOC 职业分类
| name | cis-nginx-v300-2-2-3 |
| description | Ensure the NGINX service account has an invalid shell (Manual) |
| category | cis-nginx |
| version | 3.0 |
| author | cyberstrike-official |
| tags | ["cis","nginx","web-server","reverse-proxy","account-security","basic-configuration"] |
| cis_id | 2.2.3 |
| cis_benchmark | CIS NGINX Benchmark v3.0.0 |
| tech_stack | ["nginx","linux","web-server"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The NGINX service account must be configured with an invalid login shell to prevent interactive access.
The NGINX service account is strictly for running daemon processes. Assigning it a valid login shell (like /bin/bash) unnecessarily expands the attack surface. If an attacker compromises the account credentials (or adds an SSH key), a valid shell facilitates interactive system access. Setting the shell to /sbin/nologin or /bin/false ensures that even with valid credentials, the system immediately rejects a login attempt.
None. Service accounts do not require interactive login capabilities for normal operation.
1. Identify the User:
nginx -T 2>/dev/null | grep -i "^user"
(Note the user, e.g., nginx)
2. Verify Shell:
Run the following command to inspect the configured shell for the identified user:
getent passwd nginx
(Replace nginx with the actual user found in step 1)
Evaluation:
Examine the last field of the output (the shell).
/sbin/nologin, /bin/nologin, or /bin/false./bin/bash, /bin/sh, or any other interactive shell listed in /etc/shells.Example Output (PASS):
nginx:x:999:988:nginx user:/nonexistent:/usr/sbin/nologin
Change the login shell for the identified user to /sbin/nologin:
usermod -s /sbin/nologin nginx
(Replace nginx with the actual user)
Official packages typically configure the user with /sbin/nologin or /bin/false by default.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 4.1 Establish and Maintain a Secure Configuration Process | Y | Y | Y |
| v7 | 5.1 Establish Secure Configurations | Y | Y | Y |
| Tactic | Technique |
|---|---|
| Privilege Escalation | T1078 - Valid Accounts |