Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: SunOS 4.1.4 fingerd

SunOS 4.1.4 fingerd

From: Andy Dills <andy_at_bigdog.fred.net>
Date: Thu, 16 May 1996 15:29:50 -0400

Just messing around I picked up a couple "logic flaws" with sun 4.1.4
fingerd. This may happen on 4.1.X, but I haven't tested, and I am not
motivated enough to check :>

I know I have seen it written up someplace about the flaw when
finger 0_at_XXX.com is done. (It shows a finger output on every user, which
as we know, can be a very useful tool to those with bad intentions)

Thus, we just added a user 0 (zero). Problem fixed.

Anyway, I have found that fingering ._at_XXX.com also yeilds the same result.

I am willing to bet that many know of this, but I thought I would go
ahead and throw it out there for those who haven't heard about these...

Andy

              -----/'[/'[/'[Andy Dills]'\]'\]'\-----
 "Founding member of the Frednet.Support" Phear the big BEAVIS!
"_THIS_ is my BOOM stick!!!!" -- That Guy from Army of Darkness
 Work:andy_at_fred.net---------->(BOFH)<--------Play:andy_at_beavis.net
                          NO MORE GAMES!!
Received on May 16 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos