home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!munnari.oz.au!bunyip.cc.uq.oz.au!brolga!ggm
- From: ggm@brolga.cc.uq.oz.au (George Michaelson)
- Subject: Re: unhappy about overloading finger
- Message-ID: <ggm.711762904@brolga>
- Sender: news@bunyip.cc.uq.oz.au (USENET News System)
- Organization: Prentice Centre, University of Queensland
- References: <ggm.711690458@brolga> <dank.711741463@blacks.jpl.nasa.gov>
- Date: Tue, 21 Jul 1992 23:55:04 GMT
- Lines: 41
-
- dank@blacks.jpl.nasa.gov (Dan Kegel) writes:
-
- >But what about 'Horton'? It fingers all the participating machines in
- >one's own domain hourly to update an e-mail address database,
- >which users then access via whois.
- >Since all the finger requests it generates are between two sites inside
- >your own domain, they should be easy to distinguish as benign.
- >Do you consider this a 'bad' use of finger?
-
- Ummmmmm.. I think I'd like to think about that one. On the whole, I'd
- have preferred 'horton' to distribute a variant of the fingerd daemon
- as a stepping stone to applying for an allocated SERVICE number from
- NIC/<whoeveritis> so that this migrates to another port.
-
- That way I know that this traffic is constrained to just that context.
-
- no... I dont trust every host within my local domain. some of these hosts
- are TCP/IP terminal servers where connect <host> <port> is legal, so people
- can be emulating a range of services by telnet-typing.
-
- >It would be impractical to make horton use something other than finger,
- >since it's whole reason for being is that it makes use of a universally
- >available protocol for gathering information & thus requires no
- >active cooperation from the participating (but anarchic) sites.
-
- This is a dual-edged sword. Deploying something as sensitive as an information
- gatherer, without requiring active consent, and to close off access requiring
- local modification.... not social behaviour methinks.
-
- I think I'm being too paranoid. This problem probably isn't that big, its
- just giving me an itchy feeling.
-
- On the whole, I think (mis)use of finger is doing more good than bad. I'd have
- preferred to see the various threads of functionality unravelled a bit more.
-
- -George
- --
- George Michaelson
- G.Michaelson@cc.uq.oz.au The Prentice Centre | There's no market for
- University of Queensland | hippos in Philadelphia
- Phone: +61 7 365 4079 QLD Australia 4072 | -Bertold Brecht
-