131
Finger daemon file read
Finger
2004/09/02
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
I increased the pattern matching performance in the version 1.1 because we don't need regulary expressions in this check. Corrected the plugin structure and added the accuracy values in 1.2
tcp
79
open|send |cat /etc/passwd\n|sleep|close|pattern_exists root:
98
This plugin was inspired by Nessus plugin.
Old finger daemons
Newer finger daemons
Wrong File Permission
The target system seems to be running a vulnerable old finger daemon. A special query beginning with a pipe sends the content of a file back. An attacker can read any file on the target system with commands like "finger |/etc/passwd@target".
The finger service, if not needed, should be disabled (in /etc/inetd.conf) or if possible firewalled. Upgrade to the latest software version to be not vulnerable anymore.
Approx. 30 minutes
Yes
http://www.nessus.org
Yes
Yes
High
6
9
8
4
High
Nessus and ATK is able to do the same and further check.
CVE-1999-0152
10126
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch