Search:     Advanced search
server monitoring

FreeBSD 4.1.1 Finger

Article ID: 10534
Last updated: 27 Jan, 2009
Views: 420
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

FreeBSD 4.1.1 Finger

This script is Copyright (C) 2000 Renaud Deraison

FamilyFinger abuses
Plugin ID10534
Bugtraq ID1803
CVE IDCVE-2000-0915

Description:

There is a bug in the remote finger service that allows anyone to read
arbitrary files on this host by doing a finger command on the name of
targeted file.

For instance :

finger /etc/passwd@target


Will display the content of /etc/passwd

Solution : disable the finger service in /etc/inetd.conf and restart the inetd
process, or upgrade your finger daemon

Risk factor : High
This article was:   Helpful | Not Helpful
Prev   Next
Finger dot at host feature     Solaris finger disclosure