Re: finger-bombing

James Seng (jseng@darwin.technet.sg)
Fri, 14 Oct 1994 09:59:40 +0800 (SST)

On Thu, 13 Oct 1994, Tony Jago wrote:
>      example: finger @brolga.cc.uq.oz.au@archie.au
>   I am not sure if this a "bug" or not but alot of system allow this sort 
>   of thing. HP-UX doesn't. SunOS does.

I don't think this is a bug. Neither it is a feature..it is a common hack 
many people knows but doesnt seem to have a serious security loophole. 

But it is a simple patch to finger.c (2 more lines of code to check for @ 
in the input stream) to disallow finger forwarding if you dont like it. 

James Seng Ching Hong ~{W/Uq:j~}	
Technet Student Consultant, Technet Unit
Internet: jseng@solomon.technet.sg