Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: SunOS 4.1.4 fingerd

Re: SunOS 4.1.4 fingerd

From: Dave Dittrich <dittrich_at_cac.washington.edu>
Date: Thu, 16 May 1996 13:04:07 -0700

On Thu, 16 May 1996, Andy Dills wrote:

> I know I have seen it written up someplace about the flaw when
> finger 0_at_XXX.com is done. (It shows a finger output on every user, which
> as we know, can be a very useful tool to those with bad intentions)
> ...
> Anyway, I have found that fingering ._at_XXX.com also yeilds the same result.

The trick, as I learned it, was to use @@XXX.com on Ultrix systems.
After a quick test, I notice that single letters and "." don't work on
Ultrix, but any digit or "@" does. Go figure. Probably some Berkeley
student had a hangover the day they coded finger?

> Thus, we just added a user 0 (zero). Problem fixed.

Looks like you'll have to add a few more users! ;)

--
Dave Dittrich                  Client Services, Computing & Communications
dittrich_at_cac.washington.edu    University of Washington
<a href="http://www.washington.edu/People/dad/">
Dave Dittrich / dittrich_at_cac.washington.edu</a>
Received on May 16 1996
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos