home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.unix.admin
- Path: sparky!uunet!decwrl!csus.edu!target.water.ca.gov!tching
- From: tching@target.water.ca.gov (Tracy Ching <SysAdmin>)
- Subject: Re: Where can I find a "fingerd" that fingers the person back?
- Message-ID: <1992Aug18.060635.29063@csus.edu>
- Sender: news@csus.edu
- Organization: California State University, Sacramento
- Distribution: usa
- Date: Tue, 18 Aug 1992 06:06:35 GMT
- Lines: 38
-
- In article <Bt5nLL.F9u@cs.psu.edu> ward@math.psu.edu (Brian Ward) writes:
- >dave@jato.jpl.nasa.gov (Dave Hayes) writes in response to barr@pop.psu.edu
- >(David Barr):
- >
- >I'm afraid that you are all missing the point (except daveb, he's just being
- >a little cruel)
- >tcp_wrappers is a helpful package to install. It will tell you of this stuff,
- >even if the other side is not running rfc931.
- >Here is a log message from tcp_wrappers on a telnet session from a site that
- >does not run rfc931:
- >Aug 17 19:14:03 baire.math.psu.edu in.telnetd[2383]: connect from a5.ima.umn.edu
- >And here is "better;" the same tcp_wrappers in effect and a log message
- >coming in from a rfc931 site:
- >Aug 15 21:13:24 lagrange.math.psu.edu in.rlogind[1296]: connect from grio@postscript.cs.psu.edu
- >
- >rfc931 is a Good Thing, by the way.
-
- I see (said the blind man to the deaf man :-). I do run a tcp
- logger that keeps track of all tcp actions listed in a secondary file
- similar to the /etc/services (on my Sun) keystroke-for-keystroke with
- real time simulation on playback. I do this because it seems that one
- machine (not on my floor or under my administration - thank the Lord)
- has been compromised by a few. Sloppy on their part. Keeping a list
- of people who finger and try to randomly telnet in or whatever helps
- me stay on top of things. This is the reason for wanting to know who
- fingers. "Who" is the info I'm after - not just the site. Altho' the
- security people were notified because we are a gov't agency, I feel
- a little prevention goes a longer way than reparations.
- I do see the advantage to the rfc931 and I am looking into it.
- > he's just being a little cruel.
- I can deal with cruelty - no prob. It seems sometimes that's
- what it takes to get an idea through when tact is at a minimum. Thanks
- for the feedback folks...
-
- And BTW, me as a sys admin is by default - not by choice. I'm
- into embedded control systems using microcontrollers. A bit detached
- from the UNIX network world, don't you think?
-
-