Finger Service Remote Information Disclosure

This script is Copyright (C) 2007-2013 Tenable Network Security, Inc.


Synopsis :

It is possible to obtain information about the remote host.

Description :

The remote host is running the 'finger' service.

The purpose of this service is to show who is currently logged into
the remote system, and to give information about the users of the
remote system.

It provides useful information to attackers, since it allows them to
gain usernames, determine how used a machine is, and see when each
user logged in for the last time.

Solution :

Comment out the 'finger' line in /etc/inetd.conf and restart the
inetd process

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)

Family: Misc.

Nessus Plugin ID: 10068 (finger.nasl)

Bugtraq ID:

CVE ID: CVE-1999-0612