☰ Categories

create prompt for audit purpose on password configuartion file for linux

create prompt for audit purpose on password configuartion file for linux & unix

CategoryUsing AI › Writing prompts
TagsDraftingReviewingDeveloper
Prompt
create prompt for audit purpose on password configuartion file for linux & unix

What this prompt does

This is a very short request for creating a prompt to audit password configuration files. It does not specify which files to inspect or what audit criteria to apply.

Model comparison

ChatGPT is the most complete and safety-aware. Gemini is practical but has a questionable permission example, while [C] is missing.

ChatGPTTop overall
46/ 50

+ Thorough scope, safeguards, and reporting format.

- Somewhat broad and omits benchmark-specific target values.

Gemini
42/ 50

+ Offers a practical input template and collection commands.

- The shadow permission example overlooks distro differences.

CriterionChatGPTGeminiLeader
Instruction following109ChatGPT +11%
Accuracy97ChatGPT +29%
Specificity109ChatGPT +11%
Structure99Tie
Right length88Tie

Scored 1–10 by gpt-5.6-sol with model names hidden (2026-09-25). This is an AI review, not a measurement.

Read full answers

We gave three models the same input and copied their answers unedited. Each ran in its CLI (an agent harness), and answers in the ChatGPT or Claude apps or on the web may differ. Outputs are in Korean.

gpt-5.6-luna (codex CLI · 에이전트 하네스) · Run on 2026-09-24

다음 프롬프트를 사용할 수 있습니다.

당신은 Linux 및 Unix 시스템 보안 감사 전문가입니다.

다음 비밀번호 관련 설정 파일을 대상으로 보안 감사를 수행하세요.

주요 대상:
- /etc/passwd
- /etc/shadow
- /etc/group
- /etc/gshadow
- /etc/login.defs
- /etc/security/pwquality.conf
- /etc/pam.d/system-auth
- /etc/pam.d/password-auth
- /etc/pam.d/common-password
- /etc/pam.d/common-auth
- /etc/pam.d/login
- SSH 설정 내 인증 관련 항목
- 운영체제별 기타 비밀번호 정책 파일

감사 목적:
1. 비밀번호 정책이 보안 기준에 부합하는지 확인
2. 취약하거나 과도하게 허용된 설정 탐지
3. 계정 및 권한 설정의 이상 여부 확인
4. Linux/Unix 배포판별 설정 차이 고려
5. CIS Benchmark, NIST SP 800-63 및 일반적인 보안 모범 사례 기준으로 평가

다음 항목을 점검하세요.

- 최소 비밀번호 길이
- 대문자, 소문자, 숫자, 특수문자 요구사항
- 비밀번호 최대 사용 기간
- 비밀번호 최소 사용 기간
- 비밀번호 만료 전 경고 기간
- 비밀번호 재사용 제한
- 계정 잠금 임계값
- 계정 잠금 지속 시간 및 해제 정책
- 비밀번호 해시 알고리즘
- /etc/shadow 파일의 권한 및 소유자
- 로그인 가능한 불필요한 계정
- UID 0 계정 존재 여부
- 비밀번호가 설정되지 않았거나 비어 있는 계정
- 만료된 계정 및 비활성 계정
- 기본 계정 및 서비스 계정의 로그인 가능 여부
- PAM 설정의 중복, 누락 또는 잘못된 순서
- root 원격 로그인 및 직접 로그인 정책
- 비밀번호 인증 우회 가능성
- 설정 간 충돌 또는 적용되지 않는 정책
- 배포판별 잘못된 파일 경로 또는 미지원 옵션
- 파일 권한 및 민감 정보 노출 여부

감사 시 다음 원칙을 준수하세요.

- 설정을 변경하거나 서비스를 재시작하지 마세요.
- 비밀번호 해시, 개인 정보 및 민감한 값을 결과에 그대로 출력하지 마세요.
- 필요한 경우 민감한 값은 마스킹하세요.
- 확인할 수 없는 사항은 추측하지 말고 “확인 불가”로 표시하세요.
- 실제 설정값과 기대 기준을 명확히 구분하세요.
- 운영 중인 시스템에 영향을 줄 수 있는 명령은 실행하지 마세요.
- OS 종류와 버전을 먼저 식별하고, 해당 환경에 적합한 기준을 적용하세요.

결과는 다음 형식으로 작성하세요.

1. 감사 대상 및 운영체제 정보
2. 종합 위험도: Critical / High / Medium / Low
3. 발견 사항 요약 표

| ID | 항목 | 실제 설정 | 기대 기준 | 위험도 | 근거 |
|----|------|-----------|-----------|--------|------|

4. 상세 발견 사항
   - 문제 설명
   - 보안 영향
   - 관련 파일 및 설정 위치
   - 근거
   - 권장 조치

5. 정상 확인 항목
6. 추가 확인이 필요한 항목
7. 우선순위별 개선 계획
   - 즉시 조치
   - 단기 조치
   - 중장기 조치

각 발견 사항에 대해 재현 가능한 읽기 전용 확인 명령을 제시하되, 실제 비밀번호나 해시 값은 출력하지 마세요.

More in this category

4 Optimized Versions of A Prompt (in Arabic)
$500/Hour AI Consultant Prompt
Adaptive Thinking Framework
Agent Organization Expert
AI Kickstart prompt