avatarTeri Radichel

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

2918

Abstract

.NetworkBrowser DisableAirDrop -<span class="hljs-type">bool</span> <span class="hljs-literal">true</span></pre></div><div id="951c" class="link-block"> <a href="https://www.tenable.com/audits/items/CIS_Apple_macOS_11_v1.2.0_L1.audit:80ac80bb04112ab0de3272245d582911"> <div> <div> <h2>2.4.12 Ensure AirDrop Is Disabled</h2> <div><h3>Audit item details for 2.4.12 Ensure AirDrop Is Disabled</h3></div> <div><p>www.tenable.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div> </div> </div> </a> </div><p id="3a32">What is interesting is that I ran this command:</p><div id="6288"><pre>lsof -<span class="hljs-selector-tag">i</span> </pre></div><p id="b47e">And I see a bunch of sharingd services running:</p><figure id="aa77"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*ny9xtUy1xqy38phoSk9whQ.png"><figcaption></figcaption></figure><p id="4556">I read those were related to air drop and thought once I disabled it they would go away, but upon restart they are still there.</p><p id="5d3b">Let’s try a complete reboot. Nope still there.</p><p id="d5ec">Next I try this command:</p><div id="105a"><pre>lsof <span class="hljs-string">| grep sharing</span></pre></div><p id="fdc6">I’m still seeing airdrop related things here:</p><figure id="993f"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*UghkwrTSYChk9fVMel3fGA.png"><figcaption></figcaption></figure><p id="362e">Well, I also found this post randomly:</p><div id="237c" class="link-block"> <a href="https://community.jamf.com/t5/jamf-pro/airdrop/m-p/280370"> <div> <div> <h2>Re: Airdrop</h2> <div><h3>can you clarify how I can add the below within jamf pro? is this within the configuration profile or is this a script…</h3></div> <div><p>community.jamf.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*XPFIG2tl9nhQDFYb)"></div> </div> </div> </a> </div><p id="2987">That says you can disable being discovered using this command:</p><div id="ef50"><pre>defaults write com.apple.<span class="hljs-keyword">sharingd </span><span class="hljs-keyword">DiscoverableMode </span><span class="hljs-string">"Off"</span></pre></div><p id="ca97">I added that to my start up script as well.</p><p id="8c9a">This is an interesting command you can use to see everything that’s loaded:</p><div id="b826"><pre> ls -al <span class="hljs-regexp">/System/</span>Library<span class="hljs-regexp">/LaunchDaemons/</span></pre></div><p id="ab08">Well I disabled a few things but mo

Options

re research to do on this point.</p><p id="94a5">Unfortunately still seeing multicast traffic blocked on 5353 and that weird LLDP traffic.</p><div id="31ae" class="link-block"> <a href="https://readmedium.com/lldp-on-ubiquiti-udm-pro-causing-network-glitches-38d59637054c"> <div> <div> <h2>LLDP on Ubiquiti UDM Pro Causing Network Glitches?</h2> <div><h3>Random issues with network cutting out and attacks on LLDP</h3></div> <div><p>medium.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/1*aUAASXkElgHq2L8VhiKrFw.png)"></div> </div> </div> </a> </div><p id="fd06">At first I was only seeing the above on when I connected to the Ubiquiti UDM Pro but now I’m seeing on another network as well. Trying to figure out what is going on there still in between other things I’d much rather be doing.</p><p id="ed93">I used to be an expert at every single thing running on my Windows system and I knew exactly what was and was not supposed to be there. I can’t say that I’m at the same level with my Macs — yet.</p><p id="ec2a">Stay tuned if you’re interested in this topic.</p><p id="cb73">Follow for updates.</p><p id="4a3a">Teri Radichel | <i>© <a href="https://2ndsightlab.com/?source=post_page---------------------------">2nd Sight Lab</a> 2023</i></p><div id="8b5f"><pre><span class="hljs-section">About Teri Radichel:

⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab</pre></div><div id="caae"><pre><span class="hljs-section">Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</span>
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation</pre></div><div id="5a42"><pre>Follow <span class="hljs-keyword">for</span> more stories like <span class="hljs-keyword">this</span>:

❤️ Sign Up my Medium Email List ❤️ Twitter: <span class="hljs-meta">@teriradichel</span> ❤️ LinkedIn: https:<span class="hljs-comment">//www.linkedin.com/in/teriradichel</span> ❤️ Mastodon: <span class="hljs-meta">@teriradichel</span><span class="hljs-meta">@infosec</span>.exchange ❤️ Facebook: 2nd Sight Lab ❤️ YouTube: @2ndsightlab</pre></div><figure id="faf5"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*H9Ew1KCl-29nZiPR.jpeg"><figcaption></figcaption></figure></article></body>

Disabling AirDrop and on MacOS

Continuing on in my saga to reduce network noise on a Mac

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

⚙️ Check out my series on Automating Cybersecurity Metrics | Code.

🔒 Related Stories: OS and IoT Security | Network Security | Apple Mac Security

💻 Free Content on Jobs in Cybersecurity | ✉️ Sign up for the Email List

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Still trying to eliminate traffic blocked on my network on my Mac.

In the last post I disabled Bonjour but was still seeing traffic on port 5353.

In this post I went seeking information on how to disable AirDrop as that is definitely not something I need or want on this particular computer.

Once again I found this information on the Tenable website. Their tool scans for such things. I’m not paid to say that or promoting it just letting you know what Tenable is if you’re not familiar. Their blog posts have been handy.

sudo -u <username> defaults write com.apple.NetworkBrowser DisableAirDrop -bool true

What is interesting is that I ran this command:

lsof -i 

And I see a bunch of sharingd services running:

I read those were related to air drop and thought once I disabled it they would go away, but upon restart they are still there.

Let’s try a complete reboot. Nope still there.

Next I try this command:

lsof | grep sharing

I’m still seeing airdrop related things here:

Well, I also found this post randomly:

That says you can disable being discovered using this command:

defaults write com.apple.sharingd DiscoverableMode "Off"

I added that to my start up script as well.

This is an interesting command you can use to see everything that’s loaded:

 ls -al /System/Library/LaunchDaemons/

Well I disabled a few things but more research to do on this point.

Unfortunately still seeing multicast traffic blocked on 5353 and that weird LLDP traffic.

At first I was only seeing the above on when I connected to the Ubiquiti UDM Pro but now I’m seeing on another network as well. Trying to figure out what is going on there still in between other things I’d much rather be doing.

I used to be an expert at every single thing running on my Windows system and I knew exactly what was and was not supposed to be there. I can’t say that I’m at the same level with my Macs — yet.

Stay tuned if you’re interested in this topic.

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2023

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
Mac
Airdrop
Disable
Command Line
Start Up
Recommended from ReadMedium