Ugidd daemon can reveal usernames on Linux machines

Risk Level: Low risk vulnerability  Low

Check or Attack Name: Ugidd Check

Platforms: Linux
Description:

The rpc.ugidd daemon is used on older Linux installations to translate between user names and user IDs. This daemon allows a remote attacker to enumerate all the users on a given machine.

Remedy:

Remove or disable the rpc.ugidd daemon, if it is not necessary in your configuration.

References:

Linux-Security Mailing List, NFS uid/gid map daemon, http://www.sonic.net/hypermail/security/mbox/0196.html


X-Force Logo
Know Your Risks