AOSX-10-001115 - The finger service must be disabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The finger service has had several security vulnerabilities in the past and is not a necessary service. It is disabled by default; enabling it would increase the attack surface of the system.

Solution

To disable the 'finger' service, run the following command:

sudo launchctl disable system/com.apple.fingerd

The system may need to be restarted for the update to take effect.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-10_Workstation_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000366, Rule-ID|SV-74159r1_rule, STIG-ID|AOSX-10-001115, Vuln-ID|V-59729

Plugin: Unix

Control ID: 328b3d83cccf0cd232ebe428641b263f506a2b284c6f475627ef13b35391804c