4.1 Disable Bonjour advertising service

Information

Bonjour can simplify device discovery from an internal rogue or compromised host. An attacker could use Bonjour's multicast DNS feature to discover a vulnerable or poorly-configured service or additional information to aid a targeted attack. Implementing this control disables the continuous broadcasting of 'I'm here!' messages. Typical end-user endpoints should not have to advertise services to other computers. This setting does not stop the computer from sending out service discovery messages when looking for services on an internal subnet, if the computer is looking for a printer or server and using service discovery. To block all Bonjour traffic except to approved devices the pf or other firewall would be needed.

Solution

Perform the following to implement the prescribed state -
1. Run the following command in Terminal-
2. defaults write /Library/Preferences/com.apple.mDNSResponder.plist
NoMulticastAdvertisementsImpact-Some applications, like Final Cut Studio and AirPort Base Station management, may not
operate properly if the mDNSResponder is turned off.

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.2

Plugin: Unix

Control ID: e2fd5489ab74d9e96aeca63676b0f00aac4adb2a5ee4728a5e769ebd53a05491