AOSX-09-000139 - SMB File Sharing must be disabled.

Information

File Sharing is non-essential and must be disabled. Enabling any service increases the attack surface for an intruder. By disabling unnecessary services, the attack surface is minimized.

Solution

To disable SMB File Sharing, run the following command:

sudo defaults write /private/var/db/launchd.db/com.apple.launchd/overrides.plist 'com.apple.smbd' -dict Disabled -bool true

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, CSCv6|9.1, Group-ID|V-58295, Rule-ID|SV-72725r1_rule, STIG-ID|AOSX-09-000139

Plugin: Unix

Control ID: c338bcfea5b804c361234c566e64a822b1411b4832b1a0a84c6652e99a5cedc6