Solaris finger bug

2007-07-28 Thread Jim Mellander
Hi all: Recently, we monitored a cracker from Eastern Europe, who ran 'finger [EMAIL PROTECTED]' against a Solaris 7 box, and got the following result: Login Name TTY IdleWhenWhere daemon ??? . . . . bin ??? pts/1 Oct 2,

Re: Solaris finger bug

2007-07-28 Thread Joep Vesseur
Jim Mellander wrote: Does anyone know of other platforms which exhibit this odd behavior? No, I think this is a Solaris-particular bug. I'd suggest to block finger requests to these old[1] hosts, or turn off the finger daemon alltogether... Joep [1] After all, Solaris 7 is from '98...