[MacTUG] SECURITY(Vulnerability): AFP Guest Access Enabled

Marlon A. Griffith m3griffi at engmail.uwaterloo.ca
Tue May 10 16:06:21 EDT 2011


Hi Dani,

In 10.4, only the drop box is shared..., and it is a one way share. Therefore, 10.4's afp guess sharing is relatively secure.  ;-)

Marlon


On 10/05/11 3:02 PM, Dani Roloson wrote:
>> Unless it's required, you should disable guest access. To do so under
>> MacOS X, go to System Preferences-->Sharing-->File Sharing, and then
>> click the Stop button.
>
> This doesn't just stop guest access but stops all access.
>
> The above isn't true for 10.6 or 10.5 anyhow
> (What's it in 10.4, Marlon? 8-)
> since it is checkbox not a Stop button.
>
> You really want System Preferences->Accounts->Guest Account
> and uncheck "Allow guests to connect to shared folders".
>
> The UNIX command for those of us with a ton of machines and Apple Remote
> Desktop is
>
> defaults write /Library/Preferences/SystemConfiguration/com.apple.smb.server All
> owGuestAccess 0
>
> Dani


More information about the MacTUG mailing list