Finger Service Remote Information Disclosure
Medium Nessus Plugin ID 10068
SynopsisIt is possible to obtain information about the remote host.
DescriptionThe remote host is running the 'finger' service.
The purpose of this service is to show who is currently logged into the remote system, and to give information about the users of the remote system. It provides useful information to attackers, since it allows them to gain usernames, determine how used a machine is, and see when each user logged in for the last time.
SolutionComment out the 'finger' line in /etc/inetd.conf and restart the inetd process