Finger dot at host feature
|
|
Article ID: 10072
Last updated: 27 Jan, 2009
|
|
|
|
Views: 382
|
|
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.
|
|
Finger dot at host feature |
|
| This script is Copyright (C) 1999 Renaud Deraison |
|
|
| Family | Finger abuses |
| Plugin ID | 10072 |
| Bugtraq ID |
|
| CVE ID | CVE-1999-0198
|
|
| Description: |
There is a bug in the remote finger service which, when triggered, allows
a user to force the remote finger daemon to display the list of the accounts
that have never been used, by issuing the request :
finger .@target
This list will help an attacker to guess the operating system type. It will
also tell him which accounts have never been used, which will often make him
focus his attacks on these accounts.
Solution : disable the finger service in /etc/inetd.conf and restart the inetd
process, or upgrade your finger service.
Risk factor : Medium |
|