Details
Guest access to shared Server Message Block (SMB) folders _MUST_ be disabled.
Turning off guest access prevents anonymous users from accessing files shared via SMB.
Solution
Run the following bash code
/usr/sbin/sysadminctl -smbGuestAccess off
----
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Access Control.This control applies to the following type of system Unix.
References
- 800-53|AC-2
- 800-53|AC-2(9)
- CCE|CCE-85319-2