AOSX-10-000055 - The operating system must enforce requirements for remote connections to the information system.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Screen Sharing feature allows remote users to view or control the desktop of the current user. A malicious user can take advantage of Screen Sharing to gain full access to the system remotely, either with stolen credentials or by guessing the username and password. Disabling Screen Sharing mitigates this risk.

Solution

To disable the 'screen sharing' service, run the following command:

sudo launchctl disable system/com.apple.screensharing

The system may need to be restarted for the update to take effect.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-10_Workstation_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000366, Rule-ID|SV-73967r1_rule, STIG-ID|AOSX-10-000055, Vuln-ID|V-59537

Plugin: Unix

Control ID: e9ea4980becbacde5d5611557de8d891d1330af316704bb839803c101f94a849