home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!haven.umd.edu!darwin.sura.net!mips!sdd.hp.com!usc!elroy.jpl.nasa.gov!jato!dave
- From: dave@jato.jpl.nasa.gov (Dave Hayes)
- Subject: Re: unhappy about overloading finger
- Message-ID: <1992Jul21.210658.22078@jato.jpl.nasa.gov>
- Reply-To: dave@jato.jpl.nasa.gov
- Organization: Jet Propulsion Lab - Pasadena, CA
- References: <ggm.711690458@brolga>
- Date: Tue, 21 Jul 1992 21:06:58 GMT
- Lines: 23
-
- ggm@brolga.cc.uq.oz.au (George Michaelson) writes:
- >To cover ourselves, we are increasingly using callback checks to
- >have trace on who fingers us.
- >Thus, we have a nasty scenario:
- > (1) automated s/w is flooding the net with fingers
- > (2) paranoia-calls are responding with fingers
- > (3) loops are likely.
- > (4) meantime, crackers are "hidden" by legitimate finger usage.
-
- What we do to avoid any "backfinger loops" is to not backfinger a host if
- we have already backfingered a host (a lock file works well for this).
- That way...the recursion stops here (so to speak).
-
- But increasingly, many sites disable "finger" service...therefore the
- "backfingers" and the "email fingers" and whatever else start to
- become less and less useful.
-
- I personally LIKE finger services...they are useful in a lot of ways.
- --
- Dave Hayes - Network & Communications Engineering - JPL / NASA - Pasadena CA
- dave@elxr.jpl.nasa.gov dave@jato.jpl.nasa.gov ...usc!elroy!dxh
-
- A great deal of thought is only a substitute for the thoughts which the
- individual would really find useful at the time.
-