AOSX-09-000140 - Apple File (AFP) Sharing must be disabled.

Information

File Sharing is non-essential and must be disabled. Enabling any service increases the attack surface for an intruder. By disabling unnecessary services, the attack surface is minimized.

Solution

To disable Apple File (AFP) Sharing, run the following command:

sudo defaults write /private/var/db/launchd.db/com.apple.launchd/overrides.plist 'com.apple.AppleFileServer' -dict Disabled -bool true

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, CSCv6|9.1, Group-ID|V-58297, Rule-ID|SV-72727r1_rule, STIG-ID|AOSX-09-000140

Plugin: Unix

Control ID: 586eda95a96352c4117d51b95a55b4b10e9fb7e037a148a232d77e8bf8c6bcfb