6.10.9 Ensure Finger Service is Not Set

Information

The Finger service should be disabled.

Rationale:

Finger is a simple TCP service dating back to the early 1970's that provides information on users logged into a system to other users on the network.

While this was a useful feature in the early days of the Internet, providing information about a router to unauthenticated users is not quite so desirable in today's Internet and presents a serious threat to the security of a JUNOS network device.

The finger daemon itself has suffered from numerous vulnerabilities across many platforms and, as with any unneeded service, should be disabled for this reason also.

Solution

The Finger service is not enabled by default, however if it has been configured on your router it can by disabled by issuing the following command from the [edit system services] hierarchy;

[edit system services]
user@host#delete finger

Default Value:

Finger is disabled on most versions of JUNOS by default. The service cannot be used on FIPS versions of JUNOS.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7b., 800-53|SI-4, CSCv7|9, CSCv7|9.2

Plugin: Juniper

Control ID: 860b1cfc8abd1f7b17866762daf1181a1cfd9401a04637f165c0f588f867e3b7