Bugtraq mailing list archives

Re: SunOS 4.1.4 fingerd


From: raskin () aoml noaa gov (Craig Raskin)
Date: Fri, 17 May 1996 14:14:03 -0400


On Fri, 17 May 1996, Taner Halicioglu wrote:

You can imagine what this will cause... :-)  I trivial fix is to look for
an '@' sign in the sent string (in in.fingerd) and deny the finger.

HP-UX 9.x does something along these lines. When you try to do:

finger @hp_machine@hp_machine

it gives you:

[hp_machine]
Remote finger not allowed: @hp_machine

**************************************************************************
Craig Raskin, raskin () aoml noaa gov  "A competent and self-confident person
Unix System Administrator            is incapable of jealousy in anything.
U.S. Dept. Of Commerce               Jealousy is invariably a symptom of
NOAA/AOML, Miami Fl.                 neurotic insecurity." -- Heinlein



Current thread: