131 Finger daemon file read Finger 2004/09/02 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.2 I increased the pattern matching performance in the version 1.1 because we don't need regulary expressions in this check. Corrected the plugin structure and added the accuracy values in 1.2 tcp 79 open|send |cat /etc/passwd\n|sleep|close|pattern_exists root: 98 This plugin was inspired by Nessus plugin. Old finger daemons Newer finger daemons Wrong File Permission The target system seems to be running a vulnerable old finger daemon. A special query beginning with a pipe sends the content of a file back. An attacker can read any file on the target system with commands like "finger |/etc/passwd@target". The finger service, if not needed, should be disabled (in /etc/inetd.conf) or if possible firewalled. Upgrade to the latest software version to be not vulnerable anymore. Approx. 30 minutes Yes http://www.nessus.org Yes Yes High 6 9 8 4 High Nessus and ATK is able to do the same and further check. CVE-1999-0152 10126 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch