4.5 Ensure nfs server is not running

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

macOS can act as an NFS fileserver. NFS sharing could be enabled to allow someone on another computer to mount shares and gain access to information from the user's computer. File sharing from a user endpoint has long been considered questionable and Apple has removed that capability from the GUI. NFSD is still part of the Operating System and can be easily turned on to export shares and provide remote connectivity to an end user computer.

Rationale:

File serving should not be done from a user desktop, dedicated servers should be used. Open ports make it easier to exploit the computer.

Solution

Ensure that the NFS Server is not running and is not set to start at boot

Stop the NFS Server

sudo nfsd disable

Remove the exported Directory listing

rm /etc/export

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Unix

Control ID: 9e45bc4a6ea897d1d14fce53f93a39e6252ee4db6857c99469ff3637c51ce5cc