Finger service |
---|
Risk Level: | Low | Check or Attack Name: finger |
---|---|---|
Platforms: | Finger Service, Windows NT | |
Description: | The finger service or daemon was detected as running. Finger can give an attacker information, such as login accounts and trusted hosts. |
|
Remedy: | Disable finger, or install a finger service or daemon that limits the type of information provided. Windows: The finger service is not native to Windows, but may be present. To stop or disable the service in Windows NT, follow these steps:
Unix: Disable the finger daemon or configure the type of information available from finger. Unix systems can use GNU finger available from ftp://prep.ai.mit.edu/pub/gnu/finger/finger-1.37.tar.gz. To disable the finger daemon when started from inetd, follow these steps:
For more information on GNU finger, download the compressed file from ftp://prep.ai.mit.edu/pub/gnu/finger/finger-1.37.tar.gz. You will need decompression and untarring utilities to use this file. |
|
References: |
Know Your Risks |