home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!charon.amdahl.com!pacbell.com!mips!swrinde!zaphod.mps.ohio-state.edu!magnus.acs.ohio-state.edu!usenet.ins.cwru.edu!tabatha!maf
- From: maf@tabatha.MAE.CWRU.EDU (Mark Fullmer)
- Newsgroups: comp.unix.admin
- Subject: Re: Where can I find a "fingerd" that fingers the person back?
- Message-ID: <1992Aug19.173219.9864@usenet.ins.cwru.edu>
- Date: 19 Aug 92 17:32:19 GMT
- References: <1992Aug18.060635.29063@csus.edu> <1992Aug18.155521.7840@Princeton.EDU>
- Sender: news@usenet.ins.cwru.edu
- Distribution: usa
- Organization: Case Western Reserve University
- Lines: 35
- Nntp-Posting-Host: tabatha.mae.cwru.edu
-
- In article <1992Aug18.155521.7840@Princeton.EDU> spencer@phoenix.princeton.edu (S. Spencer Sun) writes:
- >In article <1992Aug18.060635.29063@csus.edu>, tching@target.water.ca.gov (Tracy Ching <SysAdmin>) writes:
- >>[among other things]
- >>I do this because it seems that one
- >>machine (not on my floor or under my administration - thank the Lord)
- >>has been compromised by a few. Sloppy on their part. Keeping a list
- >>of people who finger and try to randomly telnet in or whatever helps
- >>me stay on top of things. This is the reason for wanting to know who
-
- [...]
-
- >
- >Any or all of the following may be wrong (someone please tell me if it
- >is), but it seems to me that knowing "where" the connect came from is
- >half the battle. After that, no matter what, you are going to need some
- >sort of cooperation from the remote site in order to track down the
- >original person, RFC931 or not. Either they're running the RFC931 thing
- >(I don't know a thing about it so apologies if I'm abusing terminology),
- >which is sort of implicit cooperation, or else you're going to need
- >their help tracking down the "who" anyway, because simply fingering back
- >isn't going to tell you who's running the finger/telnet/whatever
- >process. It will just tell you who's logged on.
- >
-
- This spoofs rfc931, fingerd logging, and fingerd finger-back.
-
- telnet random.host.edu 79
- user@host.to.query
-
- ---
-
- fingerd just passes the line to finger.
-
- mark
-