GEN003860 - The system must not have the finger service active.

Information

The finger service provides information about the system's users to network clients. This information could expose information that could be used in subsequent attacks.

Solution

Edit /etc/inetd.conf and comment out the finger service line. Restart the inetd service.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-4, CAT|III, CCI|CCI-001551, Rule-ID|SV-27440r1_rule, STIG-ID|GEN003860, Vuln-ID|V-4701

Plugin: Unix

Control ID: 5cfe49304a76880aca9d2b7df90f216d98606ad5f38162d504ba74e68468916a