Vulnerability Development mailing list archives

Re: report finger gives long list of users


From: "Schott, Erik (CORP, GEAccess)" <Erik.Schott () GEACCESS COM>
Date: Wed, 28 Mar 2001 10:49:13 -0700

Don't forget to pkill -HUP inetd, too, to make inetd re-read inetd.conf.
Otherwise, the change won't take effect.

g GE Access - Education Services
____________________________________________

Erik J. Schott
Technical Instructor
379 Thornall Street, 4th Floor
Edison, NJ  08837
732-767-0639 Office
732-767-0746 Fax
erik.schott () geaccess com


-----Original Message-----
From: Robert G. Ferrell [mailto:root () rgfsparc cr usgs gov]
Sent: Wednesday, March 28, 2001 9:41 AM
To: VULN-DEV () securityfocus com
Subject: Re: report finger gives long list of users


I can confirm this "feature" on solaris 8.

"finger 0@localhost" & "finger 1234567@localhost" both return the list of
users.

Well, not to flaunt the obvious, but the best solution to this is

# grep finger /etc/inetd.conf

#finger stream  tcp     nowait  nobody  /usr/sbin/in.fingerd    in.fingerd

;-)

Cheers,

RGF

Robert G. Ferrell, CISSP
http://rferrell.home.texas.net/rgflit.html
========================================
 Who goeth without humor goeth unarmed.
========================================


Current thread: