2.6.2 Ensure Guest Access to Shared Folders Is Disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Allowing guests to connect to shared folders enables users to access selected shared folders and their contents from different computers on a network.

Not allowing guests to connect to shared folders mitigates the risk of an untrusted user doing basic reconnaissance and possibly using privilege escalation attacks to take control of the system.

Solution

Run the following commands to verify that shared folders are not accessible to guest users:

% /usr/bin/sudo /usr/sbin/sysadminctl -smbGuestAccess off

Impact:

Unauthorized users could access shared files on the system.

See Also

https://workbench.cisecurity.org/benchmarks/17466