home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!das.wang.com!wang!news
- From: Tom Fitzgerald <fitz@wang.com>
- Subject: Re: unhappy about overloading finger
- Organization: Mail to News Gateway at Wang Labs
- Date: Wed, 22 Jul 92 21:40:48 EDT
- Message-ID: <199207230140.AA18677@fnord.wang.com>
- References: <ggm.711690458@brolga>
- Sender: news@wang.com
- Lines: 47
-
- ggm@brolga.cc.uq.oz.au (George Michaelson) writes:
-
- > (1) automated s/w is flooding the net with fingers
- > (2) paranoia-calls are responding with fingers
- > (3) loops are likely.
-
- Anybody that does back-fingers has to worry about loops, for sure. The
- best thing to do might be to keep a log of recent backfingers and not
- refinger anybody that's been hit in the last minute.
-
- > (4) meantime, crackers are "hidden" by legitimate finger usage.
-
- Make finger useless to crackers, and this won't be a problem.
-
- The advantages of finger to crackers is it lets them find login names,
- identify accounts that haven't been used for a while, and get the human
- name for the account so they can try looking up spousal names and such in
- the phone book, as potential passwords. The best way to counteract these
- is 1) have finger look up substrings of the mailing address, not the login
- name, and don't report the login name, 2) don't report the time of last
- login, and 3) make sure nobody is using a spouse name as a password.
-
- The finger daemon here reports a user's human name, mailing address,
- whether they're currently logged on (so you can try a talk (but you already
- have to know the user's login name)), and the .plan file. A finger without
- a user name prints a polite message to contact me. I like this scheme.
-
- > I would prefer
- > to see an explicit 'distributed information' protocol to replace finger
- > being used for:
- >
- > email address lookup
- > directory service call
- > generalised information checks
-
- whois does this, but too few people have whois clients. Most name-brand
- DOS TCP/IP packages, and all Unixes that I know of, have finger. Many
- Unixes, and most (nearly all?) DOS packages are missing whois. And nobody
- has a client for any alternative protocol....
-
- I'm wondering what to do about the person who ran "finger \*@das.wang.com"
- from an outside site today. Anybody know if there are finger daemons that
- screw up on user "*"?
-
- --
- Tom Fitzgerald Wang Labs fitz@wang.com "I went to the universe today;
- 1-508-967-5278 Lowell MA, USA It was closed...."
-