Cis Ubuntu1604 V200 2 1 13

Ensure HTTP Proxy Server is not installed

cyberstrikeus Updated

File contents

2.1.13 Ensure HTTP Proxy Server is not installed (Automated)

Description

Squid is a standard proxy server used in many distributions and environments.

Rationale

If there is no need for a proxy server, it is recommended that the squid proxy be deleted to reduce the potential attack surface.

Audit Procedure

Command Line

Run the following command to verify squid is not installed:

dpkg -s squid | grep -E '(Status:|not installed)'

Expected Result

dpkg-query: package 'squid' is not installed and no information is available

Remediation

Command Line

Run the following command to remove squid:

apt purge squid

Default Value

squid is not installed on minimal server installations. Several HTTP proxy servers exist. These and other services should be checked.

References

  1. CIS Controls v7 - 9.2 Ensure Only Approved Ports, Protocols and Services Are Running

Profile

  • Level 1 - Server
  • Level 1 - Workstation

cyberstrikeus/cyberstrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Operating_Systems/Ubuntu/cis-ubuntu-linux-16-04-lts-benchmark-v2/cis-ubuntu1604-v200-2-1-13 commit 482d17409c

Frequently asked questions

npx skillmds@latest add cyberstrikeus/cis-ubuntu1604-v200-2-1-13