6.1.4 Disable 'Allow guests to connect to shared folders' - AFP Sharing

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Allowing guests to connect to shared folders enables users to access selected shared folders and their contents from different computers on a network.

Rationale:

Not allowing guests to connect to shared folders mitigates the risk of an untrusted user doing basic reconnaissance and possibly use privilege escalation attacks to take control of the system.

Solution

Perform the following to implement the prescribed state:

1. Open System Preferences
2. Select Users & Groups
3. Select Guest User
4. Uncheck Allow guests to connect to shared folders

Alternatively:

For AFP sharing:

1. Run the following command in Terminal:

sudo defaults write /Library/Preferences/com.apple.AppleFileServer guestAccess -bool no

For SMB sharing:

1. Run the following command in Terminal:

sudo defaults write /Library/Preferences/SystemConfiguration/com.apple.smb.server AllowGuestAccess -bool no

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: Unix

Control ID: e54eaaa35de02d62ca06aac0414d4297e826783996e9c84d3cb86f39e14309d1